Open tlimoncelli opened 3 years ago
i have problem with the same import, my organization uses a dependency vulnerability check and give me some issues.
We should reopen and address this in some way
https://github.com/golang/appengine/releases/tag/v2.0.4 includes https://github.com/golang/appengine/pull/314, which should have this fixed. Haven't verified it yet.
Any progress on this issue?
https://github.com/golang/appengine/releases/tag/v2.0.4 should have this fixed. Could you share more details in case I missed anything?
Ideally you should switch github.com/golang/protobuf
to google.golang.org/protobuf
There is also code that is relying on this library github.com/golang/protobuf
https://github.com/golang/appengine/blob/a080531dcab843de8cd8a4156b7fa1e14ebd68da/user/user.go#L12
https://github.com/golang/appengine/blob/a080531dcab843de8cd8a4156b7fa1e14ebd68da/mail/mail.go#L27
ACK. I will try to share an update early next week. Sorry for not being able to stay on top of this issue.
@jinglundong do you have an update? Since the oauth2 package depends on appengine, the import of the deprecated package is spread across the half go universe (https://github.com/golang/oauth2/blob/master/go.mod)
Can we get some update on when we can expect not to download & compile 2 versions of the same thing?
Is anyone assigned to this?
This project imports
github.com/golang/protobuf
which is obsolete. Are there plans to switch togoogle.golang.org/protobuf
?