Skip to content

fix(security): resolve gosec findings keeping Security Scanning red on main #1354

Description

@cristim

With govulncheck (#1343) and npm audit (#1345) now green, the Security Scanning job's remaining failure is the gosec static-analysis step. Likely pre-existing gosec debt newly surfaced (earlier steps used to fail first). Run gosec ./... per the CI job config, triage each finding (real vuln vs false positive), fix real ones, and justify suppressions individually with #nosec + reason (no blanket excludes). Part of the main-CI-green effort alongside #1342 (Lint).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions