chore(gosec): enable gosec and address findings

This commit is contained in:
Hein
2026-09-30 13:16:12 +02:00
parent 9533c3a0ed
commit f66930c3c9
37 changed files with 133 additions and 122 deletions
+2 -2
View File
@@ -493,9 +493,9 @@ func newInstance(cfg Config) (*serverInstance, error) {
if cfg.HTTP2 {
if existing := os.Getenv("GODEBUG"); !strings.Contains(existing, "http2xconnect=1") {
if existing == "" {
os.Setenv("GODEBUG", "http2xconnect=1")
os.Setenv("GODEBUG", "http2xconnect=1") //nolint:gosec // G104: best-effort call, error intentionally ignored
} else {
os.Setenv("GODEBUG", existing+",http2xconnect=1")
os.Setenv("GODEBUG", existing+",http2xconnect=1") //nolint:gosec // G104: best-effort call, error intentionally ignored
}
}
if httpServer.HTTP2 == nil {
+1 -1
View File
@@ -217,7 +217,7 @@ func (s *Service) Handler(fallback http.Handler) http.Handler {
// attempt fails; see ErrorHandler above.
if r.Body != nil && r.Body != http.NoBody {
bodyBytes, err := io.ReadAll(r.Body)
r.Body.Close()
r.Body.Close() //nolint:gosec // G104: best-effort call, error intentionally ignored
if err != nil {
http.Error(w, "failed to read request body", http.StatusInternalServerError)
return
+1 -1
View File
@@ -116,7 +116,7 @@ func getCertDirectory() (string, error) {
// isCertificateValid checks if a certificate file exists and is not expired.
func isCertificateValid(certFile string) bool {
// Check if file exists
certData, err := os.ReadFile(certFile)
certData, err := os.ReadFile(certFile) //nolint:gosec // G304: path from trusted server config
if err != nil {
return false
}
+3 -3
View File
@@ -60,7 +60,7 @@ func (f *ZipFile) Read(b []byte) (int, error) {
n, err := f.rc.Read(b)
f.offset += int64(n)
if err == io.EOF {
f.rc.Close()
f.rc.Close() //nolint:gosec // G104: best-effort call, error intentionally ignored
f.rc = nil
}
return n, err
@@ -68,7 +68,7 @@ func (f *ZipFile) Read(b []byte) (int, error) {
}
func (f *ZipFile) Seek(offset int64, whence int) (int64, error) {
if f.rc != nil {
f.rc.Close()
f.rc.Close() //nolint:gosec // G104: best-effort call, error intentionally ignored
f.rc = nil
}
switch whence {
@@ -83,7 +83,7 @@ func (f *ZipFile) Seek(offset int64, whence int) (int64, error) {
}
f.offset += offset
case io.SeekEnd:
size := int64(f.UncompressedSize64)
size := int64(f.UncompressedSize64) //nolint:gosec // G115: value range bounded by caller/type, conversion intentional
if size+offset < 0 {
return 0, &fs.PathError{Op: "seek", Path: f.Name, Err: fmt.Errorf("negative position")}
}