The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running git remote get-url origin
.
If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
{ "nvd_published_at": "2024-09-19T11:15:10Z", "cwe_ids": [ "CWE-522" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-09-19T17:30:13Z" }