Follow-up to #1363 (owner suggestion). The gosec binary version, not the GitHub action wrapper, decides findings. Newer gosec (v2.27.x) has materially better G115 bounds-check recognition and improved G304 analysis, so a number of the current rule-specific #nosec annotations (added next to real guards) should no longer be needed.
Scope: bump the pinned version in .github/workflows/ci.yml (and scripts/gosec-hook.sh from #1376 - keep both pins identical); re-scan all 6 Go modules; REMOVE every #nosec the new version no longer requires (verify each by temporarily removing it and re-scanning); KEEP the genuinely-intentional ones (G101 env-var-name/constant false positives, TOTP SHA-1 compat) with their justifications - those are audit trail, not debt. Zero behavior changes to production code; suppress-count strictly decreases. Per feedback_gosec_nosec_not_nolint + no-masking directive.
Follow-up to #1363 (owner suggestion). The gosec binary version, not the GitHub action wrapper, decides findings. Newer gosec (v2.27.x) has materially better G115 bounds-check recognition and improved G304 analysis, so a number of the current rule-specific #nosec annotations (added next to real guards) should no longer be needed.
Scope: bump the pinned version in .github/workflows/ci.yml (and scripts/gosec-hook.sh from #1376 - keep both pins identical); re-scan all 6 Go modules; REMOVE every #nosec the new version no longer requires (verify each by temporarily removing it and re-scanning); KEEP the genuinely-intentional ones (G101 env-var-name/constant false positives, TOTP SHA-1 compat) with their justifications - those are audit trail, not debt. Zero behavior changes to production code; suppress-count strictly decreases. Per feedback_gosec_nosec_not_nolint + no-masking directive.