-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update module github.com/securego/gosec/v2 to v2.20.0 #444
Update module github.com/securego/gosec/v2 to v2.20.0 #444
Conversation
Hi @renovate[bot]. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
decc6ed
to
6e1955c
Compare
6e1955c
to
2d63fa1
Compare
2d63fa1
to
d730172
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
d730172
to
ff578cd
Compare
🤖 To deploy this PR, run the following command:
|
/retest-required Serial tests should be unblocked now. |
ff578cd
to
7c06bca
Compare
7c06bca
to
99d0e03
Compare
This is failing We need to be using https://pkg.go.dev/go/[email protected]#IsGenerated at least. |
Need to land #491 before this will start passing. |
99d0e03
to
d436ff9
Compare
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
d436ff9
to
7372bc0
Compare
🤖 To deploy this PR, run the following command:
|
We need to be using at least golang 1.21 to bump this version because gosec is calling a function of golang's standard library that was introduced in 1.21 - https://pkg.go.dev/go/[email protected]#IsGenerated |
7372bc0
to
f939eac
Compare
🤖 To deploy this PR, run the following command:
|
f939eac
to
3f5dd7e
Compare
🤖 To deploy this PR, run the following command:
|
/test e2e-aws-serial The serial tests ran successfully, but cleanup failed on a networking issues after the suite was done. |
The trivy issue will get fixed on #548 lands. |
/retest-required |
Trivy scanning should be fixed now that #548 landed. |
3f5dd7e
to
6e1a908
Compare
🤖 To deploy this PR, run the following command:
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: renovate[bot], rhmdnd, Vincent056 The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This PR contains the following updates:
v2.17.0
->v2.20.0
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
securego/gosec (github.com/securego/gosec/v2)
v2.20.0
Compare Source
Changelog
6fbd381
Catch os.ModePerm permissions in os.WriteFiledc5e5a9
Add a unit test to detect the false negative in rule G306 for os.ModePerm permissions417a44c
Add filepath.EvalSymlinks to clean functions in rule G304d34f8b7
chore(deps): update all dependencies8658b8e
Update Go to version 2.22.3 in CI and released3b2359
chore(deps): update module golang.org/x/text to v0.15.0cf29d54
chore(deps): update all dependencies09d62bd
chore(deps): update module github.com/onsi/gomega to v1.33.03b23ec8
Update to go 1.22.231009c3
chore(deps): update all dependenciesdaf6f67
chore(deps): update module github.com/onsi/ginkgo/v2 to v2.17.1e27f442
chore(deps): update all dependencies5513615
fix(helpers/goversion): get from go.mod43b8b75
chore: fix function nameaccd7a1
chore(deps): update all dependencies48aa72e
Format the imports using the gci toolb6df69c
Fixup: delete unused variableccb0a08
Fix test: update test to comply with the spec of generated sources3a0ea51
Refactor: use standard function to check if a file is generated11c3252
Fix lint warningsbe378e6
Add support for math/rand/v2 added in Go 1.2236878a9
Skip the G601 tests for Go version 1.22903c75b
Update go version to 1.22.1 and 1.21.8f25ccd9
Ignore 'implicit memory aliasing' rule for Go 1.22+582e91a
chore(deps): update all dependencies198a40c
chore(deps): update module golang.org/x/tools to v0.18.0c824a5d
fix(hardcoded): remove duplicatedStripe API Key
d13d7da
Update gosec version to v2.19.0 in the Github actionv2.19.0
Compare Source
Changelog
26e57d6
Update CI to go version 1.22e60b8d8
chore(deps): update all dependencies1285eb7
chore(deps): update all dependenciescf4ab3e
chore(deps): update all dependencies277553c
chore(deps): update all dependencies57ec76b
chore(deps): update all dependencies8fa46c1
chore(deps): update dependency babel-standalone to v7.23.753aa3f7
chore(deps): update module golang.org/x/crypto to v0.17.0 [security]187adab
chore(deps): update all dependenciese1f27ba
chore(deps): update actions/setup-go action to v52aad3f0
Fix lint warnings by properly formatting the files0e2a618
chore: Refactor Sample Code to Separate Filesbc03d1c
Update go version to 1.21.5 and 1.20.12 (#1084)79a6b47
chore(deps): update all dependencies (#1080)eb256a7
Ignore the issues from generated files when using the analysis framework (#1079)43b7cbf
Update README with upload-sarif v2 (#1078)fece498
chore(deps): update dependency babel-standalone to v7.23.424c614b
Added ppc64le supportc736581
chore(deps): update all dependencies3188e3f
Ensure ignores are handled properly for multi-line issues6d56592
Update Go to version 1.21.4 and 1.20.11870103b
chore(deps): update module golang.org/x/text to v0.14.0b50e493
chore(deps): update all dependencies2f9965b
Remove the hardcoded GOOS value when building the Linux binary to enable support for container image for ARMfa1b74d
Avoid allocations with(*regexp.Regexp).MatchString
64bbe90
Fix some typosd9071e3
Update local installation instructions by removing the details for Go 1.165d837bc
Update gosec version to 2.18.2 in the actionv2.18.2
Compare Source
Changelog
55d7949
Disable dot-imports in revive linter4656817
chore(deps): update module github.com/onsi/gomega to v1.28.15567ac4
Run the gosec with data race detector active during testsa239758
Fix data race in the analyzerc06903a
Fix test that checks the overriden nosec directivebde2619
Clean global state in flgs testse108c56
Format the filee298388
Update README with details which describe the current behaviour of #nosecd8a6d35
Ensure the ignores are parsed before analysing the package7846db0
chore(deps): update all dependencies8e0cf8c
Update gosec to version 2.18.1 in the action6b12a71
Update cosign version to v2.2.0v2.18.1
Compare Source
Changelog
0ec6cd9
Refactor how ignored issues are trackedf338a98
Restrict the maximum depth when tracking the slice bounds7e2d8d3
Handle empty ssa results074353a
Handle gracefully any panic that occurs when building the SSA representation of a packageec31a3a
Fix typoa11eb28
Handle new function when getting the call info in case is overriden5b7867d
Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1037)dd08f99
Update to Go 1.21.3 and 1.20.10 (#1035)616520f
Update the list of unsafe functions detected by the unsafe rule (#1033)3952187
Update the action to use gosec version v2.18.0 (#1029)2b62dd1
Use a step ID in github release action to get the digest of the image (#1028)v2.18.0
Compare Source
Changelog
53fc0c3
Update to go version 1.21.2 and 1.20.9 (#1027)7f7c47f
chore(deps): update all dependencies (#1026)d864a91
Enable gochecknoinits; fix lint issues; use consts for some vars (#1022)09cf6ef
Fix typos in struct fields, comments, and docs (#1023)665e87b
chore(deps): update all dependencies4def3a4
Fix lint warning0d332a1
Add a new rule which detects when a file is created with os.Create but the configured permissions are less than 0666293d887
Fix lint warningsac482cb
Update ginkgo to latest versione02e2f6
Redesign and reimplement the slice out of bounds check using SSA code representatione1278f9
docs: add reMarkable to users listf6a6496
chore(deps): update all dependenciesaebe20c
Drop support for go 1.19.x since go team doesn't ship anymore security fixes for it7a98537
Update to latest go versionb192f06
chore(deps): update all dependencies (#1011)6c93653
Fix hardcoded_credentials rule to only match on more specific patterns (#1009)325eb19
chore(deps): update all dependencies (#1008)beef125
Exclude maps from slince bounce check rule (#1006)21d13c9
Ignore struct pointers in G601 (#1003)85005c4
Update gosec image version to 2.17.0 in the Github action (#1002)6a2c5e1
Update cosign to version v2.1.1 (#1000)Configuration
📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.