golang-observability
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecurityreferences/rum.md
MEDIUMSecurityMEDIUM
references/rum.md
No clear malware or deliberate supply-chain attack is present. The code documents expected analytics integrations, but the displayed privacy endpoints have a potentially serious authorization gap because URL-provided user IDs are used for export and deletion without visible access control. Additional risks include inconsistent consent enforcement, trust of client-supplied correlation headers, and transmission of potentially sensitive order data to third parties. These risks are conditional on absent middleware or surrounding authorization not shown in the fragment.
Confidence: 96%Severity: 70%
Audit Metadata