style: suppress gosec G703/G704 taint false positives with justification
Some checks failed
check / check (push) Failing after 42s
Some checks failed
check / check (push) Failing after 42s
The v2.12.2 gosec ruleset's new path-traversal (G703) and SSRF (G704) taint checks flag os.Stat/os.Remove/os.Rename calls on paths that are never attacker-controlled: our own temp files created immediately before in the same function, content-hash- or cache-key-derived storage paths, the operator-supplied config search path, and the already SSRF-guarded upstream fetch (protected by ssrfSafeDialer at the transport layer). Each suppression carries the rule ID and a one-line justification, matching this repo's existing gosec nolint convention in internal/imgcache/storage.go. No behavior change.
This commit is contained in:
@@ -233,6 +233,7 @@ func (f *HTTPFetcher) Fetch(ctx context.Context, url string) (*FetchResult, erro
|
||||
|
||||
startTime := time.Now()
|
||||
|
||||
//nolint:gosec // G704: dialer enforces SSRF protection (ssrfSafeDialer)
|
||||
resp, err := f.client.Do(req)
|
||||
|
||||
fetchDuration := time.Since(startTime)
|
||||
|
||||
Reference in New Issue
Block a user