github.com/hashicorp/go-getter

govv1.8.6

Package for downloading things from a string URL using a variety of protocols.

License MPL-2.0weak copyleft43 versions109 maintainers0 deps1,815 weekly dl
hashicorp/go-getter
48
/ 100
Health
do not use

github.com/hashicorp/go-getter has critical vulnerabilities — do not use

Update to >= 2.1.0 to fix known vulnerabilities

  • 3 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
25/25
maintenance
6/20
popularity
0/25
security
12/15
maturity
5/15
community
Vulnerabilities
5
1 critical3 high1 low
Advisories (5)
SeverityIDSummaryFixed in
highCVE-2022-26945HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion2.1.0
highCVE-2022-26945HashiCorp go-getter unsafe downloads could lead to arbitrary host access2.1.0
highCVE-2022-26945HashiCorp go-getter unsafe downloads2.1.0
criticalCVE-2022-26945HashiCorp go-getter command injection2.1.0
unknownCVE-2022-26945Resource exhaustion in github.com/hashicorp/go-getter and related modules2.1.0

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/hashicorp/go-getter

Last updated · 2026-04-02T06:32:15Z

github.com/hashicorp/go-getter — Health Score 48/100 | DepScope