Secret values can be printed to the --debug log when using a a custom publisher.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2024-2482"
}{
"imports": [
{
"symbols": [
"Run"
],
"path": "github.com/goreleaser/goreleaser/internal/shell"
},
{
"symbols": [
"Pipe.Run",
"catalogArtifact"
],
"path": "github.com/goreleaser/goreleaser/internal/pipe/sbom"
},
{
"symbols": [
"Execute",
"executeCommand"
],
"path": "github.com/goreleaser/goreleaser/internal/exec"
}
]
}