Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Privacy about SponsorLink with GitInfo #299

Closed
masterminh219 opened this issue Aug 9, 2023 · 5 comments
Closed

Privacy about SponsorLink with GitInfo #299

masterminh219 opened this issue Aug 9, 2023 · 5 comments
Labels

Comments

@masterminh219
Copy link

Describe the Bug

Since I'm using GitInfo and I'm aware that Moq privacy has been raised at: https://github.com/moq/moq/issues/1372,

Can we confirm that GitInfo does not affect or not? (I found that there is a dependency with SponsorLink)

@GerardSmit
Copy link

GitInfo is also effected, since it has a dependency to SponsorLink.

Since v3.0.0-alpha SponsorLink was added to this repository: #217
Even worse, GitInfo v3.0.1 till v3.1.2 used to validate if you're a sponsor with your email address instead of the hash (https://github.com/devlooped/SponsorLink/blob/main/releases.md#whats-changed-11).

If you're using a version earlier than v3.0.0 you're not affected.

@BinToss
Copy link

BinToss commented Aug 10, 2023

SponsorLink is also a dependency of ThisAssembly.Constants which GitInfo relies on.

@NiKiZe
Copy link

NiKiZe commented Aug 11, 2023

SponsorLink is malware, any package that uses SponsorLink will be flagged as such as well.
Same developers so not surprising.

@kellenff
Copy link

GitInfo is in the same org as SpysorLink, so I doubt it'll be removed

@kzu kzu closed this as completed Aug 29, 2023
@kzu
Copy link
Member

kzu commented Aug 29, 2023

Dependency gone for a while now.

@devlooped devlooped locked and limited conversation to collaborators Sep 11, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

6 participants