)]}'
{
  "commit": "f50490d1ec34312c55a9efdacd118009bbd4f21e",
  "tree": "6c7935a704e282aaf8ad6c343385e46243175db8",
  "parents": [
    "7a0cfdab1f61f858614f645c78cbd30f6b636fcf"
  ],
  "author": {
    "name": "Damien Neil",
    "email": "dneil@google.com",
    "time": "Mon Jun 29 12:08:55 2026 -0700"
  },
  "committer": {
    "name": "Damien Neil",
    "email": "dneil@google.com",
    "time": "Mon Jun 29 14:31:48 2026 -0700"
  },
  "message": "font: document (lack of) security hardening in font packages\n\nMalicious images are in our threat model, but at this time\nmalicious fonts are not.\n\nChange-Id: I3edbf8ee83c946d2530ec71abb6db3a06a6a6964\nReviewed-on: https://go-review.googlesource.com/c/image/+/795381\nReviewed-by: Nicholas Husin \u003cnsh@golang.org\u003e\nReviewed-by: Nicholas Husin \u003chusin@google.com\u003e\nLUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com \u003cgolang-scoped@luci-project-accounts.iam.gserviceaccount.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "694ac47bfe99317350fda49b0ddf143337b6375b",
      "old_mode": 33188,
      "old_path": "font/opentype/opentype.go",
      "new_id": "72e83f0a2058daa42e9ed1350dfad897d2a40c4d",
      "new_mode": 33188,
      "new_path": "font/opentype/opentype.go"
    },
    {
      "type": "modify",
      "old_id": "858b0f646be78848aacd3e9ad00e9fa0dceb536f",
      "old_mode": 33188,
      "old_path": "font/plan9font/plan9font.go",
      "new_id": "1822ab52de59b46238f8d051fd5588d5818c9947",
      "new_mode": 33188,
      "new_path": "font/plan9font/plan9font.go"
    },
    {
      "type": "modify",
      "old_id": "d1ef8a6a0844652337ad4b62aee537580402d96a",
      "old_mode": 33188,
      "old_path": "font/sfnt/sfnt.go",
      "new_id": "103aa436ea8163c00c64833cf8fb727f49f51c52",
      "new_mode": 33188,
      "new_path": "font/sfnt/sfnt.go"
    }
  ]
}
