Skip to content

Consider removing easyjson dependency due to sanction concerns #52

@alexandear

Description

@alexandear

This project has a direct dependency on github.com/mailru/easyjson, a Go library with maintainers based in Russia and affiliated with VK Group. VK Group has known ties to the Russian government and a history of cooperating with Russian security services, including sharing user data.

According to the Hunted Labs report, "The Russian Open Source Project That We Can’t Live Without", this dependency poses a significant supply chain risk. A compromised easyjson library could lead to severe consequences, including:

  • Supply chain backdoors
  • Remote code execution
  • Espionage
  • Data exfiltration
  • Potential "kill switch" functionality

To mitigate these risks, I propose to remove this indirect dependency.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions