Skip to content

tech-debt: migrate off deprecated google.CredentialsFromJSON (SA1019) via GCP SDK upgrade #80

Description

@cristim

Summary

internal/credentials/resolver.go:453 calls the deprecated google.CredentialsFromJSON (staticcheck SA1019). It is currently suppressed with a justified //nolint:staticcheck because the replacement API requires a GCP SDK upgrade:

creds, err := google.CredentialsFromJSON(ctx, raw, gcpCloudPlatformScope) //nolint:staticcheck // SA1019: google.CredentialsFromJSON: replacement API requires GCP SDK upgrade; credentials are operator-controlled bytes

Why deferred (not urgent)

SA1019 flags CredentialsFromJSON because it does not validate the credential configuration — a risk when the config comes from an untrusted source. Here the input is operator-controlled bytes from the credential store, so the risk is mitigated and the suppression is legitimate for now. This is tech-debt, not an active vulnerability.

Work

  • Upgrade the relevant golang.org/x/oauth2/google (and any coupled GCP SDK) dependency to a version exposing the non-deprecated replacement (e.g. credentials.DetectDefault / the newer cloud.google.com/go/auth flow), migrate the call, and drop the //nolint:staticcheck.
  • Verify GCP credential resolution still works end-to-end after the migration.

Reference

Introduced/kept during the lint-debt cleanup (LeanerCloud/cloud-commitments-cli#1364). Grep guard: git grep -n "CredentialsFromJSON" internal/credentials/.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions