You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Apr 29, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
Apr 30, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Apr 30, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 1, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
May 12, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 12, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
May 14, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 15, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
May 18, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 19, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
May 22, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 23, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
May 28, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.26.1
Update module github.com/securego/gosec/v2 to v2.26.1
May 29, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.26.1
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Jun 1, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Update module github.com/securego/gosec/v2 to v2.27.1
Jun 2, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.27.1
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Jun 11, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Update module github.com/securego/gosec/v2 to v2.27.1
Jun 12, 2026
renovateBot
changed the title
Update module github.com/securego/gosec/v2 to v2.27.1
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Jun 18, 2026
renovateBot
changed the title
chore(deps): update module github.com/securego/gosec/v2 to v2.27.1
Update module github.com/securego/gosec/v2 to v2.27.1
Jun 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.22.11βv2.27.1Release Notes
securego/gosec (github.com/securego/gosec/v2)
v2.27.1Compare Source
Changelog
9e6a984Downgrade google lib to avoid min Go version bump (#β1687)v2.27.0Compare Source
Changelog
0a5c650Downgrade the jsonschema dep to v0.13.0 due to incompatibility with anthropick-sdk-go (#β1686)b48e668Update all dependencies (#β1685)bd17b25Downgrade the github.com/invopop/jsonschema v0.13.0 to solve incopatibility with anthropic-sdk (#β1683)c6f8c3dUpdate all dependencies (#β1682)5676cbcUpdate vulnerabilities alerts for indirect dependenciesce167d4Pin dependencies (#β1681)74b726dSkip pining for my reposa68f882Update renovate configuration2f8791bFix typoad3778aUpdate branch config in renovate configb1583feMigrate config renovate.json (#β1678)139e33dUpdate renovate to refresh the branch creationf3c03ebUpdate the renovate branch prefix85814f2Update renovate config to pin the actions dependencies by digests (#β1676)55f0519Migrate the html remport to react v19. (#β1675)6ad4476Manually update version to fix renovate (#β1674)8f88312feat: integrate Atlas Cloud provider (#β1672)6351b0cRefactor error position parsing to support path with colon. (#β1673)de65614Add two options to require rule ID and justificaiton for inline annotations (#β1671)e354c57Fix false positive in G118 when cancel is stored in a slice/map (#β1670)4161f0bchore(go): update supported Go versions to 1.25.10 and 1.26.3 (#β1669)b4f2934Harden the github workflows and action (#β1665)b7aca26Fix justification delimiter in annotation format doc (#β1661)945bce7Update all dependencies (#β1664)5f4eec9Update action to use gosec version v2.26.1 (#β1660)v2.26.1Compare Source
Changelog
4a3bd8aUpdate cosign to v3.0.6 (#β1659)v2.26.0Compare Source
v2.25.0Compare Source
Changelog
223e19bchore(deps): bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#β1617)b23a9e5fix: allow barry action to access secrets on fork PRs (#β1616)355cfa5fix: reduce G117 false positives for custom marshalers and transformed values (#β1614) (#β1615)744bfb5Add barry security scanner as a step in the CI (#β1612)4fde15dchore(deps): update all dependencies (#β1611)dec52c4fix: prevent taint analysis hang on packages with many CHA call graph edges (#β1608) (#β1610)a0de8b6Add some skills for claude code to automate some tasks (#β1609)c2dfcecAdd G701-G706 rule-to-CWE mappings and CWE-117, CWE-918 entries (#β1606)8aec3f4fix: skip SSA analysis on ill-typed packages to prevent panic (#β1607)1ced32dPort G120 from SSA-based to taint analysis (fixes #β1600, #β1603) (#β1605)befce8dfix(G118): eliminate false positive for package-level cancel variables (#β1602)b7b2c7bfeat: add G124 rule for insecure HTTP cookie configuration (#β1599)6e66a94feat: add G709 rule for unsafe deserialization of untrusted data (#β1598)e7ea237feat: add G708 rule for server-side template injection via text/template (#β1597)8895462fix(G118): eliminate false positive when cancel is called via struct field in a closure (#β1596)619ce21Fix infinite recursion in interprocedural taint analysis (#β1594)0e0eb17Fix G118 false positive when cancel is stored in returned struct field (#β1593)59a9da0Fix G118 false positive on cancel called inside goroutine closure (#β1592)cbf46b8fix(analyzer): per-package rule instantiation eliminates concurrent map crash (#β1589)c6c3ba8chore(deps): update all dependencies (#β1588)c709ed8fix(G118): treat returned cancel func as called (fixes #β1584) (#β1585)fa74dd7chore(go): update supported Go versions to 1.25.8 and 1.26.1 (#β1583)cd1f29eUpdate the README with the correct version of the Github action for gosec (#β1582)5887aeechore(deps): update all dependencies (#β1579)6641fcfFix G115 false positives for guarded int64-to-byte conversions (#β1578)3c9c3daUpdate the container image migration notice (#β1576)973e94echore(action): bump gosec to 2.24.7 (#β1575)v2.24.7Compare Source
Changelog
bb17e42Ignore nosec comments in action integration workflow to generate some warnings (#β1573)e1502adAdd a workflow for action integration test (#β1571)f8691bdfix(sarif): avoid invalid null relationships in SARIF output (#β1569)ade1d0echore: migrate gosec container image references to GHCR (#β1567)v2.24.6Compare Source
Changelog
88835e8Update gorelease to use the latest cosign bundle argument (#β1565)v2.24.5Compare Source
v2.24.4Compare Source
v2.24.3Compare Source
v2.24.2Compare Source
v2.24.1Compare Source
v2.24.0Compare Source
Changelog
271492bfix: G704 false positive on const URL (#β1551)1341aeafix(G705): eliminate false positive for non-HTTP io.Writer (#β1550)f2262c8G120: avoid false positive when MaxBytesReader is applied in middleware (#β1547)5b580c7Fix G602 regression coverage for issue #β1545 and stabilize G117 TOML test dependency (#β1546)eba2d15taint: skipcontext.Contextarguments during taint propagation to fix false positives (#β1543)a6381c1test: add missing rules to formatter report tests (#β1540)fea9725chore(deps): update all dependencies (#β1541)f3e2facRegenrate the TLS config rule (#β1539)200461fImprove documentation (#β1538)078a62aExpand analyzer-core test coverage for orchestration, go/analysis adapter logic, and taint integration (#β1537)ffdc620Add unit tests for CLI orchestration, TLS config generation, and SSA cache behavior (#β1536)c13a486Add G707 taint analyzer for SMTP command/header injection (#β1535)f61ed31Add G123 analyzer for tls.VerifyPeerCertificate resumption bypass risk (#β1534)b568aa1Add G122 SSA analyzer for filepath.Walk/WalkDir symlink TOCTOU race risks (#β1532)1735e5afix(G602): avoid false positives for range-over-array indexing (#β1531)caf93d0Improve taint analyzer performance with shared SSA cache, parallel analyzer execution, and CI regression guard (#β1530)bd11fbefix: taint analysis false positives with G703,G705 (#β1522)e34e8ddExtend the G117 rule to cover other types of serialization such as yaml/xml/toml (#β1529)b940702Fix the G117 rule to take the JSON serialization into account (#β1528)4f84627(docs) fix justification format (#β1524)36ba72bAdd G121 analyzer for unsafe CORS bypass patterns in CrossOriginProtection (#β1521)238f982Add G120 SSA analyzer for unbounded form parsing in HTTP handlers (#β1520)89cde27Add G119 analyzer for unsafe redirect header propagation in CheckRedirect callbacks (#β1519)14fdd9cFix G115 false positives and negatives (Issue #β1501) (#β1518)cec54ecchore(deps): update all dependencies (#β1517)2b2077eAdd G118 SSA analyzer for context propagation failures that can cause goroutine/resource leaks (#β1516)a7666f3Add G113: Detect HTTP Request Smuggling via conflicting headers (CVE-2025-22891, CWE-444) (#β1515)47f8b52Add G408: SSH PublicKeyCallback Authentication Bypass Analyzer (#β1513)4f1f362Add more unit tests to improve coverage (#β1512)9344582Improve test coverage in various areas (#β1511)8d1b2c6Imprve the test coverage (#β1510)993c1c4Fix incorrect detection of fixed iv in G407 (#β1509)8668b74Add support for go 1.26.x and removed support for go 1.24.x (#β1508)514225cFix the sonar report to follow the latest schema (#β1507)000384efix: broken taint analysis causing false positives (#β1506)616192cfix: panic on float constants in overflow analyzer (#β1505)79956a3fix: panic when scanning multi-module repos from root (#β1504)5736e8bfix: G602 false positive for array element access (#β1499)1b7e1e9Update gosec to version v2.23.0 in the Github action (#β1496)v2.23.0Compare Source
Changelog
398ad54feat: Support for adding taint analysis engine (#β1486)6eacd5cchore(deps): update all dependencies (#β1494)181a7cbchore(deps): update all dependencies (#β1494)e2fa6abchore(deps): update all dependencies (#β1488)eb252baFix G602 analyzer panic that kills gosec process (#β1491)20d71a0update go version to 1.25.7 (#β1492)a631af8Fix URL regexp and remove redundant Google regex patterns (#β1485)8968502feat: implement global cache usage in rules (#β1480)04f729cchore(deps): update module google.golang.org/genai to v1.43.0 (#β1484)ade0e8frefactor: optimize nosec parsing and reduce allocations (#β1478)d24bbf7Fix SARIF artifactChanges null validation error (#β1483)15cba7ffeat: optimize GetCallInfo with per-package sync.Pool caching (#β1481)5288673feat: implement entropy pre-filtering to optimize secret detection (#β1479)d9a9bcdfeat: ensure GoVersion is cached using sync.Once (#β1477)516260aFix #β1240: nosec comments now work with trailing open brackets (#β1475)be0fd6dDebug Build Profiling Support: Code improvement suggestions for PR#1471 (#β1476)b579523Update the go version to 1.25.6 and 1.24.12 (#β1474)bd3c738G115: Enhance RangeAnalyzer with constant propagation and chained arithmetic support (#β1470)6897b36chore(deps): update all dependencies (#β1473)9f20212feat: support path-based rule exclusions via exclude-rules (#β1465)726d847Optimize analyzer with parallel package processing (#β1466)3150b28feat: add goanalysis package for nogo (#β1449)7284e15Refactor Analyzers: Unify Range Logic & Optimize Allocations (#β1464)7a4ccefOptimize G115, G602, G407 analyzers to reduce allocations and memory (#β1463)833d791refactor(g115): improve coverage (#β1462)0cc9e01Refine G407 to improve detection and coverage of hardcoded nonces (#β1460)303f84dchore(deps): update all dependencies (#β1461)7387d22Refactor rules to use callListRule base structure (#β1458)52f5dbffeat(slice): enhance slice bounds analysis with dynamic bounds handling (#β1457)649e2c8remove deprecated ast.Object (#β1455)35a92b4feat(sql): enhance SQL injection detection with improved string concatenation checks (#β1454)bc9d2bcfeat(rules): enhance subprocess variable checks (#β1453)8a5404efeat(resolve): enhance TryResolve to handle KeyValueExpr, IndexExpr, and SliceExpr (#β1452)0f6f21cfeat: add secrets serialization G117 (#β1451)717706efeat(rules): add support for detecting high entropy strings in composite literals (#β1447)082deb6whitelist crypto/rand Read from error checks (#β1446)095d529chore(deps): update all dependencies (#β1443)c073629Improve slice bound check (#β1442)538a05cdocs: add documentation for using gosec with private modules (#β1441)2580437chore(deps): update all dependencies (#β1440)872b331docs: add G116 rule description to README (#β1439)dcf93a8Update GitHub action to gosec 2.22.11 (#β1438)Configuration
π Schedule: (in timezone Asia/Tokyo)
π¦ Automerge: Disabled by config. Please merge this manually once you are satisfied.
β» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
π Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.