Skip to content

ci: pre-commit gosec hook and CI enforce DIFFERENT gosec rule sets [cli part] #1394

Description

@cristim

Duplication audit found a FUNCTIONAL divergence, not just DRY: scripts/gosec-hook.sh (#1376) excludes ~15 gosec rules and hand-mirrors ci.yml's module list, while the CI Security Scanning job runs gosec with NO -exclude. So a local pre-commit pass does NOT predict CI (the hook is more lenient), defeating the hook's purpose (feedback_gosec_nosec_not_nolint says local+CI must agree). Plus version drift: ci.yml on main is v2.26.1, the hook is v2.28.0, #1384 bumps CI to v2.28.0.

Fix: single source of truth - a shared scripts/run-gosec.sh (version + module list + flags) invoked by BOTH the pre-commit hook and the CI job, so they enforce IDENTICAL rules. Land #1384 (CI->v2.28.0) before/with #1376 so versions match. Remove the hook's extra -exclude list (or apply the same list in CI, deliberately).

Findings from the 2026-09-02 codebase audit

Added by an automated audit of 3c0f8ac94048a2c36fce5ccddee54e6c4849a5cd (tip of origin/main). Each item below was reported by one reviewer and independently confirmed by a second that did not write it. Full report: docs/audits/codebase-audit-2026-09-02.md.

A14-012 (medium)

A third divergent gosec rule set exists beyond the hook and CI. Makefile:159 runs gosec -fmt=json -out=gosec-report.json -exclude=G101,G104,G115,G204,G301,G304,G402,G505 ./..., while ci.yml:694-705 runs gosec with no -exclude at all. So make security-scan silences eight rule classes, including the TLS and InsecureSkipVerify-adjacent ones, and a clean local run predicts nothing about the CI job. A shared scripts/run-gosec.sh should be invoked from the Makefile target too, not just from the hook and the CI job, or the divergence simply moves. The separate defect that this target's trailing echo swallows gosec's exit status is already tracked in #1594's Makefile item. Audit finding A14-012.

Scope after the split

The CUDly monorepo was split into four repos. This issue is now scoped to only cloud-commitments-cli's own scripts/gosec-hook.sh, .github/workflows/ci.yml, and Makefile. The version-drift part of the original finding is already moot here: both the hook and CI are pinned to gosec v2.28.0. The functional rule-set divergence (hook excludes 15 rules, CI excludes none, Makefile excludes a different 8) is still live in this repo.

The identical divergence exists in the other three split repos; each got its own tracking issue:

Acceptance criteria (this repo)

  • A single scripts/run-gosec.sh (version + module list + -exclude flags in one place) is added and invoked by the pre-commit hook, the CI job, and the Makefile security-scan-go target.
  • The hook's and Makefile's extra -exclude lists are either removed (rules enforced everywhere) or deliberately applied in CI too, with the decision documented in the script.
  • A local make security-scan-go (or pre-commit hook run) and the CI job report the same findings for the same commit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions