Hi,

I happened to notice https://rustsec.debian.net/ recently, and that relies
on "Static-Built-Using" to track which disclosed vulnerability impacts
what package.

Given that Go world is also statically linked, does such a tracker makes
sense for the Go team as well?

PS: I am not volunteering to do so myself, but wanted to know the opinion, and
maybe look for volunteers to do this, if this is of interest.

Thanks,
Nilesh

Reply via email to