chore(gosec): enable gosec and address findings

This commit is contained in:
Hein
2026-09-30 13:16:12 +02:00
parent 9533c3a0ed
commit f66930c3c9
37 changed files with 133 additions and 122 deletions
+4 -4
View File
@@ -686,7 +686,7 @@ func (p *PgSQLInsertQuery) Exec(ctx context.Context) (res common.Result, err err
i++
}
query := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)",
query := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", //nolint:gosec // G201: table identifier is internal/validated; values use placeholders
p.tableName,
strings.Join(columns, ", "),
strings.Join(placeholders, ", "))
@@ -736,7 +736,7 @@ func (p *PgSQLInsertQuery) Scan(ctx context.Context, dest interface{}) (err erro
i++
}
query := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)",
query := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", //nolint:gosec // G201: table identifier is internal/validated; values use placeholders
p.tableName,
strings.Join(columns, ", "),
strings.Join(placeholders, ", "))
@@ -886,7 +886,7 @@ func (p *PgSQLUpdateQuery) Exec(ctx context.Context) (res common.Result, err err
i++
}
query := fmt.Sprintf("UPDATE %s SET %s",
query := fmt.Sprintf("UPDATE %s SET %s", //nolint:gosec // G201: table identifier is internal/validated; values use placeholders
p.tableName,
strings.Join(setClauses, ", "))
@@ -997,7 +997,7 @@ func (p *PgSQLDeleteQuery) Exec(ctx context.Context) (res common.Result, err err
recordQueryMetrics(p.metricsEnabled, "DELETE", p.schema, p.entity, p.tableName, startedAt, err)
}()
query := fmt.Sprintf("DELETE FROM %s", p.tableName)
query := fmt.Sprintf("DELETE FROM %s", p.tableName) //nolint:gosec // G201: table identifier is internal/validated; values use placeholders
if len(p.whereClauses) > 0 {
query += " WHERE " + strings.Join(p.whereClauses, " AND ")
@@ -13,7 +13,7 @@ import (
// Example demonstrates how to use the PgSQL adapter
func ExamplePgSQLAdapter() error {
// Connect to PostgreSQL database
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return fmt.Errorf("failed to open database: %w", err)
@@ -155,7 +155,7 @@ func (u User) TableName() string {
// ExampleWithModel demonstrates using models with the PgSQL adapter
func ExampleWithModel() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err
@@ -51,7 +51,7 @@ func (c Comment) TableName() string {
// ExamplePreload demonstrates the Preload functionality
func ExamplePreload() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err
@@ -79,7 +79,7 @@ func ExamplePreload() error {
// ExamplePreloadRelation demonstrates smart PreloadRelation with auto-detection
func ExamplePreloadRelation() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err
@@ -148,7 +148,7 @@ func ExamplePreloadRelation() error {
// ExampleJoinRelation demonstrates explicit JOIN loading
func ExampleJoinRelation() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err
@@ -185,7 +185,7 @@ func ExampleJoinRelation() error {
// ExampleScanModel demonstrates ScanModel with struct destinations
func ExampleScanModel() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err
@@ -221,7 +221,7 @@ func ExampleScanModel() error {
// ExampleCompleteWorkflow demonstrates a complete workflow with preloading
func ExampleCompleteWorkflow() error {
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable"
dsn := "postgres://username:password@localhost:5432/dbname?sslmode=disable" //nolint:gosec // G101: false positive: identifier/example, not a credential
db, err := sql.Open("pgx", dsn)
if err != nil {
return err