[image] font: document (lack of) security hardening in font packages

0 views
Skip to first unread message

Damien Neil (Gerrit)

unread,
Jun 29, 2026, 5:31:53 PM (2 days ago) Jun 29
to goph...@pubsubhelper.golang.org, golang-...@googlegroups.com, Nicholas Husin, Nicholas Husin, golang...@luci-project-accounts.iam.gserviceaccount.com, Roland Shoemaker, Neal Patel, golang-co...@googlegroups.com

Damien Neil submitted the change

Change information

Commit message:
font: document (lack of) security hardening in font packages

Malicious images are in our threat model, but at this time
malicious fonts are not.
Change-Id: I3edbf8ee83c946d2530ec71abb6db3a06a6a6964
Reviewed-by: Nicholas Husin <n...@golang.org>
Reviewed-by: Nicholas Husin <hu...@google.com>
Files:
  • M font/opentype/opentype.go
  • M font/plan9font/plan9font.go
  • M font/sfnt/sfnt.go
Change size: S
Delta: 3 files changed, 21 insertions(+), 0 deletions(-)
Branch: refs/heads/master
Submit Requirements:
Open in Gerrit
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: merged
Gerrit-Project: image
Gerrit-Branch: master
Gerrit-Change-Id: I3edbf8ee83c946d2530ec71abb6db3a06a6a6964
Gerrit-Change-Number: 795381
Gerrit-PatchSet: 2
Gerrit-Owner: Damien Neil <dn...@google.com>
Gerrit-Reviewer: Damien Neil <dn...@google.com>
Gerrit-Reviewer: Nicholas Husin <hu...@google.com>
Gerrit-Reviewer: Nicholas Husin <n...@golang.org>
Gerrit-CC: Neal Patel <neal...@google.com>
Gerrit-CC: Roland Shoemaker <rol...@golang.org>
open
diffy
satisfied_requirement
Reply all
Reply to author
Forward
0 new messages