Open cyrilc-pro opened 6 months ago
A PR would be most welcome :)
What do you suggest? Can we just remove the zip file?
Historically, Go exe files have been known to raise false vulnerabilities by scanners.
This code was added quite a while back and now there's native fuzzing available in the Go toolchain. It would be great if you want to revamp the entire fuzzing part - remove all the old code, and redo fuzzing using the new way.
Otherwise, I don't think there's a big downside in keeping them.
This package includes a file
fuzz/fuzz-fuzz.zip
which includes binaries (sonar.exe
,cover.exe
). These files are detected as vulnerable by security scanners as they were compiled with Go 1.14.1. I think this is file should not be committed into Git.