-
Notifications
You must be signed in to change notification settings - Fork 25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update module github.com/securego/gosec to v2 #861
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
ℹ Artifact update noticeFile name: scripts/go/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
grafanarenovatebot
bot
force-pushed
the
grafanarenovatebot/github.com-securego-gosec-2.x
branch
from
August 30, 2024 08:04
2576b52
to
576cec6
Compare
mem
approved these changes
Aug 30, 2024
ka3de
added a commit
that referenced
this pull request
Sep 2, 2024
* k6runner: always log error code and string to user's logger * Update module golang.org/x/sync to v0.8.0 (#812) * Update module golang.org/x/net to v0.28.0 (#813) * Build(deps): Bump the prometheus-go group across 1 directory with 2 updates (#827) * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.22.0 (#817) * Update module go.k6.io/k6 to v0.53.0 (#823) * Update dependency grafana/k6 to v0.53.0 * Update module github.com/miekg/dns to v1.1.62 * Update github.com/grafana/loki/pkg/push digest to 9315b3d * Update golang.org/x/exp digest to 9b4947d * Update github.com/securego/gosec/v2 digest to ab3f6c1 * Update github.com/grafana/loki/pkg/push digest to 246a1df * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * Build(deps): Bump github.com/prometheus/client_golang * Update module github.com/securego/gosec to v2 * renovate: fix grafana-build-tools dependency regex * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * drone: regenerate pipelines * Add with-browser Docker image (#829) * Update module github.com/prometheus/prometheus to v0.54.1 (#843) * Update module github.com/prometheus/common to v0.56.0 (#849) * Build(deps): Bump google.golang.org/grpc from 1.65.0 to 1.66.0 * Build(deps): Bump github.com/prometheus/common * renovate: group prometheus-go updates * renovate: enable default managers * renovate: add `dependencies` label to PRs * dependabot: remove * Update renovatebot/github-action action to v40.2.7 (#859) * go: upgrade to 1.23 (#838) * Update module github.com/golangci/golangci-lint to v1.60.0 (#825) * Update alpine Docker tag to v3.20 (#858) * Update actions/checkout action to v4.1.7 (#857) * Dockerfile: pin hash of debian:stable-slim image (#828) * Update module github.com/mccutchen/go-httpbin/v2 to v2.14.1 (#860) * Update module github.com/securego/gosec to v2 (#861) * feat: Validate browser capability (#809) Signed-off-by: ka3de <danijs12@hotmail.com>
Merged
ka3de
added a commit
that referenced
this pull request
Sep 2, 2024
* k6runner: always log error code and string to user's logger * Update module golang.org/x/sync to v0.8.0 (#812) * Update module golang.org/x/net to v0.28.0 (#813) * Build(deps): Bump the prometheus-go group across 1 directory with 2 updates (#827) * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.22.0 (#817) * Update module go.k6.io/k6 to v0.53.0 (#823) * Update dependency grafana/k6 to v0.53.0 * Update module github.com/miekg/dns to v1.1.62 * Update github.com/grafana/loki/pkg/push digest to 9315b3d * Update golang.org/x/exp digest to 9b4947d * Update github.com/securego/gosec/v2 digest to ab3f6c1 * Update github.com/grafana/loki/pkg/push digest to 246a1df * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * Build(deps): Bump github.com/prometheus/client_golang * Update module github.com/securego/gosec to v2 * renovate: fix grafana-build-tools dependency regex * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * drone: regenerate pipelines * Add with-browser Docker image (#829) * Update module github.com/prometheus/prometheus to v0.54.1 (#843) * Update module github.com/prometheus/common to v0.56.0 (#849) * Build(deps): Bump google.golang.org/grpc from 1.65.0 to 1.66.0 * Build(deps): Bump github.com/prometheus/common * renovate: group prometheus-go updates * renovate: enable default managers * renovate: add `dependencies` label to PRs * dependabot: remove * Update renovatebot/github-action action to v40.2.7 (#859) * go: upgrade to 1.23 (#838) * Update module github.com/golangci/golangci-lint to v1.60.0 (#825) * Update alpine Docker tag to v3.20 (#858) * Update actions/checkout action to v4.1.7 (#857) * Dockerfile: pin hash of debian:stable-slim image (#828) * Update module github.com/mccutchen/go-httpbin/v2 to v2.14.1 (#860) * Update module github.com/securego/gosec to v2 (#861) * feat: Validate browser capability (#809) Signed-off-by: ka3de <danijs12@hotmail.com>
ka3de
added a commit
that referenced
this pull request
Sep 2, 2024
* k6runner: always log error code and string to user's logger * Update module golang.org/x/sync to v0.8.0 (#812) * Update module golang.org/x/net to v0.28.0 (#813) * Build(deps): Bump the prometheus-go group across 1 directory with 2 updates (#827) * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.22.0 (#817) * Update module go.k6.io/k6 to v0.53.0 (#823) * Update dependency grafana/k6 to v0.53.0 * Update module github.com/miekg/dns to v1.1.62 * Update github.com/grafana/loki/pkg/push digest to 9315b3d * Update golang.org/x/exp digest to 9b4947d * Update github.com/securego/gosec/v2 digest to ab3f6c1 * Update github.com/grafana/loki/pkg/push digest to 246a1df * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * Build(deps): Bump github.com/prometheus/client_golang * Update module github.com/securego/gosec to v2 * renovate: fix grafana-build-tools dependency regex * Update ghcr.io/grafana/grafana-build-tools Docker tag to v0.23.0 * drone: regenerate pipelines * Add with-browser Docker image (#829) * Update module github.com/prometheus/prometheus to v0.54.1 (#843) * Update module github.com/prometheus/common to v0.56.0 (#849) * Build(deps): Bump google.golang.org/grpc from 1.65.0 to 1.66.0 * Build(deps): Bump github.com/prometheus/common * renovate: group prometheus-go updates * renovate: enable default managers * renovate: add `dependencies` label to PRs * dependabot: remove * Update renovatebot/github-action action to v40.2.7 (#859) * go: upgrade to 1.23 (#838) * Update module github.com/golangci/golangci-lint to v1.60.0 (#825) * Update alpine Docker tag to v3.20 (#858) * Update actions/checkout action to v4.1.7 (#857) * Dockerfile: pin hash of debian:stable-slim image (#828) * Update module github.com/mccutchen/go-httpbin/v2 to v2.14.1 (#860) * Update module github.com/securego/gosec to v2 (#861) * feat: Validate browser capability (#809) Signed-off-by: ka3de <danijs12@hotmail.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.0.0-20200401082031-e946c8c39989
->v2.20.0
Release Notes
securego/gosec (github.com/securego/gosec)
v2.20.0
Compare Source
Changelog
6fbd381
Catch os.ModePerm permissions in os.WriteFiledc5e5a9
Add a unit test to detect the false negative in rule G306 for os.ModePerm permissions417a44c
Add filepath.EvalSymlinks to clean functions in rule G304d34f8b7
chore(deps): update all dependencies8658b8e
Update Go to version 2.22.3 in CI and released3b2359
chore(deps): update module golang.org/x/text to v0.15.0cf29d54
chore(deps): update all dependencies09d62bd
chore(deps): update module github.com/onsi/gomega to v1.33.03b23ec8
Update to go 1.22.231009c3
chore(deps): update all dependenciesdaf6f67
chore(deps): update module github.com/onsi/ginkgo/v2 to v2.17.1e27f442
chore(deps): update all dependencies5513615
fix(helpers/goversion): get from go.mod43b8b75
chore: fix function nameaccd7a1
chore(deps): update all dependencies48aa72e
Format the imports using the gci toolb6df69c
Fixup: delete unused variableccb0a08
Fix test: update test to comply with the spec of generated sources3a0ea51
Refactor: use standard function to check if a file is generated11c3252
Fix lint warningsbe378e6
Add support for math/rand/v2 added in Go 1.2236878a9
Skip the G601 tests for Go version 1.22903c75b
Update go version to 1.22.1 and 1.21.8f25ccd9
Ignore 'implicit memory aliasing' rule for Go 1.22+582e91a
chore(deps): update all dependencies198a40c
chore(deps): update module golang.org/x/tools to v0.18.0c824a5d
fix(hardcoded): remove duplicatedStripe API Key
d13d7da
Update gosec version to v2.19.0 in the Github actionv2.19.0
Compare Source
Changelog
26e57d6
Update CI to go version 1.22e60b8d8
chore(deps): update all dependencies1285eb7
chore(deps): update all dependenciescf4ab3e
chore(deps): update all dependencies277553c
chore(deps): update all dependencies57ec76b
chore(deps): update all dependencies8fa46c1
chore(deps): update dependency babel-standalone to v7.23.753aa3f7
chore(deps): update module golang.org/x/crypto to v0.17.0 [security]187adab
chore(deps): update all dependenciese1f27ba
chore(deps): update actions/setup-go action to v52aad3f0
Fix lint warnings by properly formatting the files0e2a618
chore: Refactor Sample Code to Separate Filesbc03d1c
Update go version to 1.21.5 and 1.20.12 (#1084)79a6b47
chore(deps): update all dependencies (#1080)eb256a7
Ignore the issues from generated files when using the analysis framework (#1079)43b7cbf
Update README with upload-sarif v2 (#1078)fece498
chore(deps): update dependency babel-standalone to v7.23.424c614b
Added ppc64le supportc736581
chore(deps): update all dependencies3188e3f
Ensure ignores are handled properly for multi-line issues6d56592
Update Go to version 1.21.4 and 1.20.11870103b
chore(deps): update module golang.org/x/text to v0.14.0b50e493
chore(deps): update all dependencies2f9965b
Remove the hardcoded GOOS value when building the Linux binary to enable support for container image for ARMfa1b74d
Avoid allocations with(*regexp.Regexp).MatchString
64bbe90
Fix some typosd9071e3
Update local installation instructions by removing the details for Go 1.165d837bc
Update gosec version to 2.18.2 in the actionv2.18.2
Compare Source
Changelog
55d7949
Disable dot-imports in revive linter4656817
chore(deps): update module github.com/onsi/gomega to v1.28.15567ac4
Run the gosec with data race detector active during testsa239758
Fix data race in the analyzerc06903a
Fix test that checks the overriden nosec directivebde2619
Clean global state in flgs testse108c56
Format the filee298388
Update README with details which describe the current behaviour of #nosecd8a6d35
Ensure the ignores are parsed before analysing the package7846db0
chore(deps): update all dependencies8e0cf8c
Update gosec to version 2.18.1 in the action6b12a71
Update cosign version to v2.2.0v2.18.1
Compare Source
Changelog
0ec6cd9
Refactor how ignored issues are trackedf338a98
Restrict the maximum depth when tracking the slice bounds7e2d8d3
Handle empty ssa results074353a
Handle gracefully any panic that occurs when building the SSA representation of a packageec31a3a
Fix typoa11eb28
Handle new function when getting the call info in case is overriden5b7867d
Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1037)dd08f99
Update to Go 1.21.3 and 1.20.10 (#1035)616520f
Update the list of unsafe functions detected by the unsafe rule (#1033)3952187
Update the action to use gosec version v2.18.0 (#1029)2b62dd1
Use a step ID in github release action to get the digest of the image (#1028)v2.18.0
Compare Source
Changelog
53fc0c3
Update to go version 1.21.2 and 1.20.9 (#1027)7f7c47f
chore(deps): update all dependencies (#1026)d864a91
Enable gochecknoinits; fix lint issues; use consts for some vars (#1022)09cf6ef
Fix typos in struct fields, comments, and docs (#1023)665e87b
chore(deps): update all dependencies4def3a4
Fix lint warning0d332a1
Add a new rule which detects when a file is created with os.Create but the configured permissions are less than 0666293d887
Fix lint warningsac482cb
Update ginkgo to latest versione02e2f6
Redesign and reimplement the slice out of bounds check using SSA code representatione1278f9
docs: add reMarkable to users listf6a6496
chore(deps): update all dependenciesaebe20c
Drop support for go 1.19.x since go team doesn't ship anymore security fixes for it7a98537
Update to latest go versionb192f06
chore(deps): update all dependencies (#1011)6c93653
Fix hardcoded_credentials rule to only match on more specific patterns (#1009)325eb19
chore(deps): update all dependencies (#1008)beef125
Exclude maps from slince bounce check rule (#1006)21d13c9
Ignore struct pointers in G601 (#1003)85005c4
Update gosec image version to 2.17.0 in the Github action (#1002)6a2c5e1
Update cosign to version v2.1.1 (#1000)v2.17.0
Compare Source
Changelog
a89e9d5
Enable go 1.21.0 in the CI build (#998)4b458c4
chore(deps): update all dependencies (#997)7d51bfe
Update to go version 1.20.7 and 1.19.12 (#993)fc2f66b
chore(deps): update all dependencies (#992)2cf2f96
chore(deps): update module github.com/onsi/gomega to v1.27.10 (#991)bf7feda
fix: correctly identify infixed concats as potential SQL injections (#987)2292ed5
chore(deps): update all dependencies (#989)fc570b6
Add a new flag terse to show only the results and summary (#986)36f6933
Switch to a maintained fork of zxcvbn module (#984)ed7b334
Fix dependencies after bot update (#983)e76ad70
chore(deps): update all dependencies (#982)3a6fd99
Update to Go version 1.19.11 and 1.20.6 (#981)ea39309
Fix and tidy the dependencies (#977)ef8f560
chore(deps): update all dependencies (#976)17b7d31
Update README file with new rule (#975)a018cf0
Feature: G602 Slice Bound Checking (#973)82364a7
chore(deps): update all dependencies (#974)abeab10
Feature: G101 match variable values and names (#971)b824c10
Update build script to go version 1.20.5022584d
chore(deps): update all dependenciesbd58600
Recognize struct field in G6011457921
Remove the depguard from the list of enabled linters1f68996
Fix typos in comments, vars and testse148465
chore(deps): update all dependencies9120883
Fix no-sec alternative tag (#962)87cc45e
Use image digest instead of tag when signing the released image with cosign (#960)6df05bd
Update gosec image version to 2.16.0 in the Github action (#959)v2.16.0
Compare Source
Changelog
c5ea1b7
Update cosign to latest version in release Github action (#958)8632a8c
chore(deps): update all dependencies (#956)ae3c2f7
Update go version in build and release scripts (#957)970cc29
chore(deps): update all dependencies (#955)47bfd4e
Update Go version to 1.20.3 (#953)440141a
chore(deps): update all dependencies (#952)7df7baa
Fix for Dockerfile smell DL3059 (#951)2ee3213
README: upgrade GitHub action in examples (#950)68b5201
enable ginkgolinter linter (#948)780ebd0
chore(deps): update all dependencies (#947)d6aeaad
correct gci linter (#946)73f0efc
remove deprecated lintersaef69b3
increase timeout to 5m6bad723
chore(deps): update all dependencies96bb741
Use the latest version6a73248
Fix some linting warnings83fc5e6
Fix lint warning8e7cf4b
Bump the go versions and golancie7bfcd1
chore(deps): update all dependencies (#942)f823a7e
Check nil pointer when variable is declared in a different filecdd3476
fix dead link to issue.go in README.md (#936)d5a9c73
Remove rule G307 which checks when an error is not handled when a file or socket connection is closed (#935)27bf0e4
Fix rule index reference into sarif report (#934)e7b896f
Bump golang.org/x/net from 0.6.0 to 0.7.04340efa
Format filef850069
Use the gosec issue in the go analysersb1fd948
Fix file formatting2071786
Update Go version in CI builds1915717
Fix method name in the commentde2c6a3
Extract the issue in its own package31e6327
Add support for Go analysis framework and SSA code representatione795d75
chore(deps): update all dependencies (#931)8aa00db
Remove the version form ci github action392e53c
Pin github action to latest release version 2.15.0ffe254e
Revert the image tag in github action until a working solution is founda0eddfb
Fix version interpolation in github action imaged22a7b6
Add gosec version as an input parameter to GitHub action (#927)2d6b0a5
Update release build script (#924)v2.15.0
Compare Source
Changelog
a459eb0
Fix dependencies after renovate update54f56c7
chore(deps): update all dependencies (#922)df14837
Update to Go 1.20 and fix unit tests (#923)b4270dd
Update Go to latest version (#920)a624254
Update hardcoded_credentials.go fix: adaper equal expr which const value at left (#917)9432e67
Fix github latest URL (#918)e85e1a7
Fix github release url (#916)7dcb8c7
chore(deps): update module github.com/onsi/ginkgo/v2 to v2.7.0 (#914)c5d217d
Update Go version in CI script (#913)5874e63
Track back when a file path was sanitized with filepath.Clean (#912)fd28036
Fix the TLS config rule when parsing the settings from a variable (#911)a522ae6
Fix build after updating the dependencies (#910)4cc97ad
chore(deps): update all dependencies (#909)05a7bc5
Fix dependencies after renovate update (#907)11898d5
chore(deps): update all dependencies (#906)f9a8bf0
Update slack badge and link (#905)dabc7dc
Auto-detect TLS MinVersion integer base (#903)c39bcdb
Adding s390x support (#902)e06bbf9
chore(deps): update all dependencies (#904)f79c584
chore(deps): update all dependencies (#898)44f484f
Additional types for bad defer check (#897)2fe6c5b
chore(deps): update all dependencies (#894)a0b7ebb
chore(deps): update all dependencies (#892)0acfbb4
Update Go version in CI scripts (#889)6a964b2
chore(deps): update all dependencies (#888)a7ad827
Allow to override build date with SOURCE_DATE_EPOCH (#887)26f0389
chore(deps): update all dependencies (#886)7f91d85
chore(deps): update all dependencies (#884)cf63541
fileperms: bitwise permission comparison (#883)v2.14.0
Compare Source
Changelog
1af1d5b
Pin release build to Go version 1.19.2 (#882)0ae0174
Refactor to support duplicate imports with different aliases (#865)a2719d3
chore(deps): update all dependencies (#881)ed38681
go.mod: ginkgo/v2 v2.3.1, golang.org/x/text v0.3.8, update go versions (#880)8466173
Update Go version to 1.19 in the makefile (#876)f9ad0d8
chore(deps): update all dependencies (#875)6cd9e62
Add CWE-676 to cwe mapping (#874)bb4a1e3
chore(deps): update all dependencies (#872)7ea37bb
Add a way to use private repositories on GitHub (#869)e244c81
chore(deps): update all dependencies (#868)e9b2781
Check go version when installing govulncheck88c23de
Check go version when running govulncheck84f6424
Add vulncheck to the test steps180fc23
chore(deps): update all dependenciesdfde579
Fix false positives for G404 with aliased packagesaaaf80c
chore(deps): update all dependenciesae58325
chore(deps): update all dependenciesa892be9
fix: add a CWE ID mapping to rule G114a319b66
chore(deps): update golang.org/x/crypto digest tobc19a97
v2.13.1
Compare Source
Changelog
19fa856
fix: make sure that nil Cwe pointer is handled when getting the CWE ID62fa4b4
test: remove white spaces from template074dc71
fix: handle nil CWE pointer in text templatev2.13.0
Compare Source
Changelog
79a5b13
chore(deps): update dependency babel-standalone to v797f03d9
chore: update module go to 1.190ba05e1
chore: fix lint warningsd3933f9
chore: add support for Go 1.194e68fb5
fix: parsing of the Go version (#844)0c8e63e
Detect use of net/http functions that have no support for setting timeouts (#842)6a26c23
Refactor SQL rules for better extensibility (#841)1b0873a
chore(deps): update module golang.org/x/tools to v0.1.12 (#840)845483e
Fix lint warning45bf9a6
Check the suppressed issues when generating the exit codea5982fb
Fix for G402. Check package path instead of package name (#838)ea6d49d
fix G204 bugs (#835)21fcd2f
Phase out support for Go 1.16 since is not supported anymore by Go team (#837)3cda47a
chore(deps): update all dependencies (#836)0212c83
chore(deps): update dependency highlight.js to v11.6.0 (#830)9a25f4e
fix: filepaths with git anywhere in them being erroneously excluded (#828)602ced7
Fix wrong location for G109 (#829)7dd9ddd
chore(deps): update golang.org/x/crypto digest to0559593
(#826)b0f3e78
fix ReadTimeout for G112 rule05f3ca8
Pin cosign-installer tov2
(#824)v2.12.0
Compare Source
Changelog
a9b0ef0
chore(deps): update all dependencies (#822)9c19cb6
Add check for usage of Rat.SetString in math/big with an overflow error (#819)fb587c1
Remove additional--update
for apk in Dockerfile (#818)c3ede62
Update x/tools to pick up fix for golang/go#51629 (#817)0a929c7
chore(deps): update all dependencies (#816)12be148
chore(deps): update all dependencies (#812)0dcc336
chore(deps): update all dependencies (#811)34d144b
Add new rule for Slowloris Attacka64cde5
Fix the dependencies after renovate upate (#806)b69c3d4
chore(deps): update all dependencies (#805)89dfdc0
Update the description message of template rule (#803)0791d31
Fix typo in ReadMe (#802)2ef1d9a
Fix build after renovate update (#800)afc9903
Fix use rule IDs to retrieve the rule config82eaa12
chore(deps): update all dependencies (#796)v2.11.0
Compare Source
Changelog
607d607
Enable Go 1.18 in the ci and release workflowsb99b5f7
Fix the lint action after upgrade (#790)8af0af7
chore(deps): update all dependencies (#789)ea5d31f
Add a recursive flag -r to skip specifying ./... path48bbf96
Adds directory traversal for Http.Dir("/")v2.10.0
Compare Source
Changelog
26f10e0
Extend the release action to sign the docker image and binary files with cosign (#781)7d539ed
feat: add concurrency option to parallelize package loading (#778)43577ce
chore(deps): update all dependenciesc0680bb
Process the code snippet before adding it to the SARIF reportdb8d98b
Updated sponsor link in README.md507f847
chore(deps): update golang.org/x/crypto commit hash to30dcbda
853e1d5
chore(deps): update all dependencies09a2941
Use the CWE name as a name in the SARIF report9399e7b
chore(deps): update all dependencies (#771)2fad8a4
Resolve the TLS min version when is declarted in the same package but in a different file1fbcf10
Add a test for tls min version defined in a different fileb12c0f6
chore(deps): update all dependencies (#765)v2.9.6
Compare Source
Changelog
1d909e2
Add db.Exec and db.Prepare to the sql rule (#763)742aa84
chore(deps): update golang.org/x/crypto commit hash to5e0467b
(#764)7be6d4e
Add os.Create to the readfile rule (#761)75cc7dc
Fix false negative for SQL injection when using DB.QueryRow.Scan() (#759)58058af
chore(deps): update dependency highlight.js to v11.4.0 (#758)9d66b0d
Fix false negatives for SQL injection in multi-line queries4c1afaa
Find G303 with filepath.Join'd temp dirs (#754)19bda8d
Find more tempdirs827fca9
build(fmt): use[
instead of[[
(#751)ad5d74d
Update to ginkgo v2 (#753)72f1145
Fix #743 (#748)63a8e78
Handle nil when looking up a file by position into a package (#747)3038a30
Add in the config file settings for exclude and include optionsbf0dd2f
chore(deps): update golang.org/x/crypto commit hash toe495a2d
(#745)2d1c1a6
Track both #nosec and #nosec rulelist for one violation (#741)e0f354a
Add the sponsors section in the README file (#740)d23ab2d
Remove space between//
and#nosec
in examples and internal usev2.9.5
Compare Source
Changelog
35af340
Fix #736 (#738)6c0b344
chore(deps): update golang.org/x/crypto commit hash to4570a08
(#737)v2.9.4
Compare Source
Changelog
b45f95f
Add support for suppressing the findings040327f
chore(deps): update all dependencies (#734)v2.9.3
Compare Source
Changelog
6a41fb9
Fix https://github.com/securego/gosec/issues/714 (#733)c95e9c2
chore(deps): update all dependencies (#731)v2.9.2
Compare Source
Changelog
e57efa8
Fix a panic in suproc rule when the declaration of the variable is not available in the AST (#728)ff17c30
Use go embed for templates (#725)3eba7b8
add openssh to docker image (#719)55c6cea
Fix crash when parsing the TLS min version value (#724)40fa36d
G303: catch with os.WriteFile, add os.Create test case (#718)873ac24
chore(deps): update all dependencies (#722)f1f0056
Spelling fixes (#717)0680c75
chore(deps): update all dependencies (#716)79c8b79
use a better naming for the variable (#715)v2.9.1
Compare Source
Changelog
6921395
Fix the SBOM generation step in the release action (#712)5a3a27a
Phase out support for go version 1.15 because current ginko is not backward compatible (#710)v2.9.0
Compare Source
v2.8.1
Compare Source
Changelog
3f800cc
Fix the unit tests (#652)df10b65
Fix gosimple lint warning (#651)731d0d5
Results must always be present in the SARIF report (#650)3c230ac
errors.go: add Hash.Write() to the white list. (#648)e72b1e5
Use of vars instead of funcc81cff0
Update all dependencies (#646)3ff0a2c
Fixes #644 (#645)e3dffd6
Update renovate configurationaa35eb5
Delete renovate.json (#642)3b1b77e
add onboarding (#640)03360ba
Update renovate configuration8a8dbec
Tidy up the dependencies (#637)3a4d09b
Update all dependencies (#635)6cde6b3
Disable cache in golangci job (#636)1256f16
Fix lint and fail on error in the ci builddbb9811
Add crypto and lint to the tools modules244adc6
Update the github ci action to use cache and matrix strategydf1249d
Update install.sh with more installation optionsaf27673
Update README.mdv2.8.0
Compare Source
Changelog
9fc8e20
Add favicon for HTML template (#628)91dae7f
Update the design of HTML reporte72f54e
Fix HTML template and display the gosec versionc3f25b8
fix html report tag styling (#623)433a674
show nosec in html report summary (#621)d040f07
Handle gosec version in SARIF report51f7411
Add arm64 support (#618)e7ac882
Update go version to 1.16 (#616)3a9a6ad
Sarif provide Snippet with Issue.Code1325319
Create dependabot.yml (#614)d8cfcd6
Allow the user to enable/disable colorisation of the text report in the stdouta8b633f
Adding stdout and verbose flags and refactor how the report is saved103c429
Enable golangcli and improve testing for formatters4df7f1c
Fix typos, Go Report link and Gofmtf4ea33d
Update how the test coverage is generatedc4f5932
Refactor : Replace Cwe with cwe.Weaknessddfa253
Define a report package with core and per format sub-packagescc83d4c
Generate the SARIF types, handle taxonomies and separate responsibilities0fa5d0b
Fix the go modules after updating to get the tests passing (#605)3763953
Migrate sonar types in a dedicated package (#604)b519743
chore(deps): update all dependencies (#599)569328e
Fix typos (#594)0695fa0
Add-u
to local install instructions (#595)7f2308b
Tidy up the moduels after updating (#593)f21b0b8
chore(deps): update all dependencies (#592)148e608
Adding KICS to USERS.md (#590)v2.7.0
Compare Source
Changelog
27a5ffb
Quiet warnings about integer truncation (#586)bf2cd23
Update all dependencies (#585)01ee764
Fix typo in USERS.md (#583)9c047e3
Add support for Go 1.16 in the CI and release workflows (#581)1fce461
fix: WriteParams rule to work also with golang 1.16 (#577)dcbcc4d
Use a more generic path for sonarqube import path (#573)2777e50
Update README with a note which describes how to import a SonarQube report (#572)897c203
Reset the state of TLS rule after each version check (#570)6c57ae1
Fix sarif formatting issues (#565)b6524ce
Update all dependenciesv2.6.1
Compare Source
Changelog
00bbbd8
Fix the release workflow to allow unsecure commandsv2.6.0
Compare Source
v2.5.0
Compare Source
Changelog
a4746e1
Update all dependencies (#533)6bd6e4b
Use $(go env GOPATH) that works even when GOPATH is not setaef335a
Fix typo in README.md0ce48a5
Reproducible junit report (#529)868556b
Update README with the correct path to tlsconfig command13519fd
Update the tls configuration generate to handle also the NSS alternative namese351067
Update all dependencies166e4f5
Update README file with some more details required to run successfully a scan with the docker imagef5cc32a
Update the Go version to 1.15 in the Makefileea0fa28
Update the Github go action version to 1.6.0feea8bb
Fix the action tag6688a97
Fix the github action for Go 1.157234349
Add Go 1.15 to the supported version and phase out the Go 1.12a3895d5
Fix typo in README file17c9555
Incorrect local installation instructions for v2f13b8bc
Add also filepath.Rel as a sanitization method for input argConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.