Some checks failed
check / check (push) Failing after 42s
The v2.12.2 gosec ruleset's new path-traversal (G703) and SSRF (G704) taint checks flag os.Stat/os.Remove/os.Rename calls on paths that are never attacker-controlled: our own temp files created immediately before in the same function, content-hash- or cache-key-derived storage paths, the operator-supplied config search path, and the already SSRF-guarded upstream fetch (protected by ssrfSafeDialer at the transport layer). Each suppression carries the rule ID and a one-line justification, matching this repo's existing gosec nolint convention in internal/imgcache/storage.go. No behavior change.
18 KiB
18 KiB