style: suppress gosec G703/G704 taint false positives with justification
Some checks failed
check / check (push) Failing after 42s

The v2.12.2 gosec ruleset's new path-traversal (G703) and SSRF (G704)
taint checks flag os.Stat/os.Remove/os.Rename calls on paths that are
never attacker-controlled: our own temp files created immediately
before in the same function, content-hash- or cache-key-derived
storage paths, the operator-supplied config search path, and the
already SSRF-guarded upstream fetch (protected by ssrfSafeDialer at
the transport layer). Each suppression carries the rule ID and a
one-line justification, matching this repo's existing gosec nolint
convention in internal/imgcache/storage.go. No behavior change.
This commit is contained in:
2026-08-09 00:37:30 +00:00
parent 08c4861cfc
commit 13e9f2c072
3 changed files with 15 additions and 10 deletions

View File

@@ -233,6 +233,7 @@ func (f *HTTPFetcher) Fetch(ctx context.Context, url string) (*FetchResult, erro
startTime := time.Now()
//nolint:gosec // G704: dialer enforces SSRF protection (ssrfSafeDialer)
resp, err := f.client.Do(req)
fetchDuration := time.Since(startTime)