The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running "git remote get-url origin".
If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3140" }
{ "imports": [ { "path": "github.com/grafana/grafana-plugin-sdk-go/build", "symbols": [ "Build.Backend", "Build.Darwin", "Build.DarwinARM64", "Build.Debug", "Build.DebugDarwinAMD64", "Build.DebugDarwinARM64", "Build.DebugLinuxAMD64", "Build.DebugLinuxARM64", "Build.DebugWindowsAMD64", "Build.Linux", "Build.LinuxARM", "Build.LinuxARM64", "Build.Windows", "Info.appendFlags", "getBuildBackendCmdInfo", "getBuildInfoFromEnvironment", "getEnvironment" ] } ] }