Skip to content

Remove indirect dependency on github.com/mailru/easyjson #3527

Open
@alexandear

Description

@alexandear

Description

This project has an indirect dependency on github.com/mailru/easyjson, a Go library with maintainers based in Russia and affiliated with VK Group. VK Group has known ties to the Russian government and a history of cooperating with Russian security services, including sharing user data.

According to the Hunted Labs report, "The Russian Open Source Project That We Can’t Live Without", this dependency poses a significant supply chain risk. A compromised easyjson library could lead to severe consequences, including:

  • Supply chain backdoors
  • Remote code execution
  • Espionage
  • Data exfiltration
  • Potential "kill switch" functionality

To mitigate these risks, I propose to remove this indirect dependency.

Dependencies that relies on easyjson (updated based on the discussion below):

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions