Temporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.
The problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.
Disable Go Modules support.
Blog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:57:15Z",
"nvd_published_at": null,
"severity": "MODERATE"
}