The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running "git remote get-url origin".
If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
{
"url": "https://pkg.go.dev/vuln/GO-2024-3140",
"review_status": "REVIEWED"
}{
"imports": [
{
"path": "github.com/grafana/grafana-plugin-sdk-go/build",
"symbols": [
"Build.Backend",
"Build.Darwin",
"Build.DarwinARM64",
"Build.Debug",
"Build.DebugDarwinAMD64",
"Build.DebugDarwinARM64",
"Build.DebugLinuxAMD64",
"Build.DebugLinuxARM64",
"Build.DebugWindowsAMD64",
"Build.Linux",
"Build.LinuxARM",
"Build.LinuxARM64",
"Build.Windows",
"Info.appendFlags",
"getBuildBackendCmdInfo",
"getBuildInfoFromEnvironment",
"getEnvironment"
]
}
]
}