Hi, I happened to notice https://rustsec.debian.net/ recently, and that relies on "Static-Built-Using" to track which disclosed vulnerability impacts what package.
Given that Go world is also statically linked, does such a tracker makes sense for the Go team as well? PS: I am not volunteering to do so myself, but wanted to know the opinion, and maybe look for volunteers to do this, if this is of interest. Thanks, Nilesh
