Package gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services ๐
active 2023-08-15 โ 2026-05-06 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 996 days from 2023-08-15 to 2026-05-06. Pushes: 5 total, peak 2 in a day. Pull requests: 18 total, peak 5 in a day. Issues: 21 total, peak 2 in a day. Comments: 47 total, peak 3 in a day. Stars: 263 total, peak 3 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 โ โ95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments โ stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| coreydaley | 15 | 4 | 7 | 2 |
| jaitaiwan | 5 | 0 | 0 | 4 |
| codecov[bot] | 5 | 0 | 0 | 5 |
| savas5445 | 5 | 0 | 5 | 0 |
| FlorianLoch | 4 | 0 | 1 | 3 |
| sudhanvaghebbale | 3 | 0 | 1 | 1 |
| matthewhughes934 | 3 | 0 | 0 | 2 |
| illume | 3 | 0 | 0 | 2 |
| AlexVulaj | 3 | 1 | 0 | 1 |
| arlando | 3 | 0 | 0 | 1 |
| bashhack | 3 | 0 | 2 | 1 |
| FiloSottile | 3 | 0 | 0 | 1 |
| shamilovstas | 2 | 0 | 0 | 1 |
| cirelli94 | 2 | 0 | 0 | 2 |
| kokoichi206 | 2 | 0 | 0 | 1 |
| Z3NTL3 | 2 | 0 | 0 | 1 |
| hazcod | 2 | 0 | 0 | 2 |
| Sang-Hyuk | 2 | 0 | 1 | 0 |
| jub0bs | 2 | 0 | 0 | 2 |
| NightTsarina | 1 | 0 | 0 | 0 |
Recent activity
Latest issues, pull requests and releases
- Issue comment#204rayjanoka2026-01-26 04:54Fix for this CVE-2025-47909 is required
- Issue comment#204hazcod2026-01-04 20:11Fix for this CVE-2025-47909 is required
- Issue comment#204stevenh2026-01-04 17:31Fix for this CVE-2025-47909 is required
- Issue comment#204hazcod2025-12-31 11:44Fix for this CVE-2025-47909 is required
- Issue comment#204shortontech2025-11-09 01:09Fix for this CVE-2025-47909 is required
- Issue comment#194bashhack2025-10-07 18:16[REFACTOR] Remove custom contains in favor of std lib impl
- Pull request#194bashhack2025-10-07 18:16
- Issue comment#188PotatoesFall2025-10-02 15:29[BUG] v.1.7.3 sameOrigin check issue for localhost over http
- Issue comment#190Midwayne2025-09-21 18:49[BUG] Forbidden - Invalid Origin in localhost
- Issue comment#202tommydehaas2025-09-05 07:21[BUG] Discrepancy between security reports?
- Issue#203a-h2025-08-09 15:05[FEATURE] Make csrf and gorilla/schema compatible with each other without additional config
- Issue#202fragglet2025-07-28 14:17[BUG] Discrepancy between security reports?
- Issue comment#190yeungon2025-07-13 02:47[BUG] Forbidden - Invalid Origin in localhost
- Issue#201Imran-imtiaz482025-07-05 13:25Security Flaw in encrypt and decrypt: In-place XOR Alters Input Data
- Pull request#200savas54452025-06-22 01:08
- Pull request#198savas54452025-06-22 00:47
- Pull request#197savas54452025-06-22 00:41
- Pull request#196savas54452025-06-22 00:37
- Pull request#195savas54452025-06-22 00:35
- Pull request#194bashhack2025-06-19 04:41
- Issue comment#190davidjunxyang2025-06-16 22:36[BUG] Forbidden - Invalid Origin in localhost
- Issue comment#190geokat2025-05-26 01:22[BUG] Forbidden - Invalid Origin in localhost
- Pull request#191me-th2025-05-16 09:06
- Issue comment#190shamilovstas2025-05-14 13:04[BUG] Forbidden - Invalid Origin in localhost
- Issue#190shamilovstas2025-05-14 12:53[BUG] <title>Forbidden - Invalid Origin in localhost
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals โ 263 stars here means stars gained during the window, not the repo's star count.