Summary
internal/credentials/resolver.go:453 calls the deprecated google.CredentialsFromJSON (staticcheck SA1019). It is currently suppressed with a justified //nolint:staticcheck because the replacement API requires a GCP SDK upgrade:
creds, err := google.CredentialsFromJSON(ctx, raw, gcpCloudPlatformScope) //nolint:staticcheck // SA1019: google.CredentialsFromJSON: replacement API requires GCP SDK upgrade; credentials are operator-controlled bytes
Why deferred (not urgent)
SA1019 flags CredentialsFromJSON because it does not validate the credential configuration — a risk when the config comes from an untrusted source. Here the input is operator-controlled bytes from the credential store, so the risk is mitigated and the suppression is legitimate for now. This is tech-debt, not an active vulnerability.
Work
- Upgrade the relevant
golang.org/x/oauth2/google (and any coupled GCP SDK) dependency to a version exposing the non-deprecated replacement (e.g. credentials.DetectDefault / the newer cloud.google.com/go/auth flow), migrate the call, and drop the //nolint:staticcheck.
- Verify GCP credential resolution still works end-to-end after the migration.
Reference
Introduced/kept during the lint-debt cleanup (LeanerCloud/cloud-commitments-cli#1364). Grep guard: git grep -n "CredentialsFromJSON" internal/credentials/.
Summary
internal/credentials/resolver.go:453calls the deprecatedgoogle.CredentialsFromJSON(staticcheck SA1019). It is currently suppressed with a justified//nolint:staticcheckbecause the replacement API requires a GCP SDK upgrade:Why deferred (not urgent)
SA1019 flags
CredentialsFromJSONbecause it does not validate the credential configuration — a risk when the config comes from an untrusted source. Here the input is operator-controlled bytes from the credential store, so the risk is mitigated and the suppression is legitimate for now. This is tech-debt, not an active vulnerability.Work
golang.org/x/oauth2/google(and any coupled GCP SDK) dependency to a version exposing the non-deprecated replacement (e.g.credentials.DetectDefault/ the newercloud.google.com/go/authflow), migrate the call, and drop the//nolint:staticcheck.Reference
Introduced/kept during the lint-debt cleanup (LeanerCloud/cloud-commitments-cli#1364). Grep guard:
git grep -n "CredentialsFromJSON" internal/credentials/.