Skip to content

ci: add pre-commit gosec hook for at-commit-time security feedback #1374

Description

@cristim

Add a pre-commit hook running gosec (pinned to the same version as CI, currently v2.26.1) so security findings surface at commit time instead of first failing in the Security Scanning CI job. Requirements: pinned version (never @latest, per feedback_ci_tool_version_pin); scan only the packages containing changed .go files (fast); respect the multi-module layout (root, pkg, providers/aws|azure|gcp, ci_cd_sanity_tests) by running gosec within the module owning each changed package; same flags as CI so local and CI verdicts agree; suppressions must use the #nosec form (see feedback_gosec_nosec_not_nolint). Complements #1363 (multi-module CI scan).

Activity

  1. cristim commented on Jul 16, 2026

    @cristim
    MemberAuthor

    Implemented in PR #1376: #1376

  2. added 2 commits that reference this issue on Jul 16, 2026
    c969733
    3f0446f
  3. added a commit that references this issue on Jul 16, 2026
    cd6562e
  4. cristim commented on Jul 16, 2026

    @cristim
    MemberAuthor

    Closed by #1376 (merged): pinned per-package gosec pre-commit hook. Rule-set alignment with CI tracked in #1394.

  5. added 2 commits that reference this issue on Sep 27, 2026
    495edd9
    be4ad42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions