Temporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.
The problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.
Disable Go Modules support.
Blog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure
If you have any questions or comments about this advisory: * Open an issue in Renovate
{ "github_reviewed_at": "2020-06-16T21:57:15Z", "github_reviewed": true, "nvd_published_at": null, "cwe_ids": [ "CWE-200" ], "severity": "MODERATE" }