{"id":"openSUSE-SU-2026:20579-1","summary":"Security update for gosec","details":"This update for gosec fixes the following issues:\n\nChanges in gosec:\n\n- Update to version 2.25.0:\n  * chore(deps): bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#1617)\n  * fix: allow barry action to access secrets on fork PRs (#1616)\n  * fix: reduce G117 false positives for custom marshalers and transformed values (#1614) (#1615)\n  * Add barry security scanner as a step in the CI (#1612)\n  * chore(deps): update all dependencies (#1611)\n  * fix: prevent taint analysis hang on packages with many CHA call graph edges (#1608) (#1610)\n  * Add some skills for claude code to automate some tasks (#1609)\n  * Add G701-G706 rule-to-CWE mappings and CWE-117, CWE-918 entries (#1606)\n  * fix: skip SSA analysis on ill-typed packages to prevent panic (#1607)\n  * Port G120 from SSA-based to taint analysis (fixes #1600, #1603) (#1605)\n  * fix(G118): eliminate false positive for package-level cancel variables (#1602)\n  * feat: add G124 rule for insecure HTTP cookie configuration (#1599)\n  * feat: add G709 rule for unsafe deserialization of untrusted data (#1598)\n  * feat: add G708 rule for server-side template injection via text/template (#1597)\n  * fix(G118): eliminate false positive when cancel is called via struct field in a closure (#1596)\n  * Fix infinite recursion in interprocedural taint analysis (#1594)\n  * Fix G118 false positive when cancel is stored in returned struct field (#1593)\n  * Fix G118 false positive on cancel called inside goroutine closure (#1592)\n  * fix(analyzer): per-package rule instantiation eliminates concurrent map crash (#1589)\n  * chore(deps): update all dependencies (#1588)\n  * fix(G118): treat returned cancel func as called (fixes #1584) (#1585)\n  * chore(go): update supported Go versions to 1.25.8 and 1.26.1 (#1583)\n  * Update the README with the correct version of the Github action for gosec (#1582)\n  * chore(deps): update all dependencies (#1579)\n  * Fix G115 false positives for guarded int64-to-byte conversions (#1578)\n  * Update the container image migration notice (#1576)\n  * chore(action): bump gosec to 2.24.7 (#1575)\n\n- Update to version 2.24.7:\n  * Ignore nosec comments in action integration workflow to generate some warnings (#1573)\n  * Add a workflow for action integration test (#1571)\n  * fix(sarif): avoid invalid null relationships in SARIF output (#1569)\n  * chore: migrate gosec container image references to GHCR (#1567)\n  * Update gorelease to use the latest cosign bundle argument (#1565)\n  * Migrate goreleaser to use the proper cosign arguments (#1564)\n  * Update the cosing to version v3.0.5 (#1563)\n  * fix(release): use existing cosign-installer action version (#1562)\n  * chore(prompts): add skill and prompt to update supported Go versions (#1561)\n  * chore(prompts): add action version update skill and prompt (#1560)\n  * fix(analyzers): avoid SSA dependency cycle blowups in issue #1555 paths (#1559)\n  * Add a SKILL and PROMPT for fixing a GitHub issue (#1558)\n  * Add a SKILL and PROMPT for generating rules with AI (#1557)\n  * fix(G120): prevent hang-like analysis blowup in wrapper protection checks (#1556)\n  * fix(G705): eliminate false positive when guard type cannot be resolved (#1554)\n  * Remove gcmurphy from funding list\n  * Extend the release workflow to push the container images also to GHCR\n  * Update to gosec to v2.24.0 in the action and fix the docker image signing (#1552)\n\n- Update to version 2.24.0:\n  * fix: G704 false positive on const URL (#1551)\n  * fix(G705): eliminate false positive for non-HTTP io.Writer (#1550)\n  * G120: avoid false positive when MaxBytesReader is applied in middleware (#1547)\n  * Fix G602 regression coverage for issue #1545 and stabilize G117 TOML test dependency (#1546)\n  * taint: skip `context.Context` arguments during taint propagation to fix false positives (#1543)\n  * test: add missing rules to formatter report tests (#1540)\n  * chore(deps): update all dependencies (#1541)\n  * Regenrate the TLS config rule (#1539)\n  * Improve documentation (#1538)\n  * Expand analyzer-core test coverage for orchestration, go/analysis adapter logic, and taint integration (#1537)\n  * Add unit tests for CLI orchestration, TLS config generation, and SSA cache behavior (#1536)\n  * Add G707 taint analyzer for SMTP command/header injection (#1535)\n  * Add G123 analyzer for tls.VerifyPeerCertificate resumption bypass risk (#1534)\n  * Add G122 SSA analyzer for filepath.Walk/WalkDir symlink TOCTOU race risks (#1532)\n  * fix(G602): avoid false positives for range-over-array indexing (#1531)\n  * Improve taint analyzer performance with shared SSA cache, parallel analyzer execution, and CI regression guard (#1530)\n  * fix: taint analysis false positives with G703,G705 (#1522)\n  * Extend the G117 rule to cover other types of serialization such as yaml/xml/toml (#1529)\n  * Fix the G117 rule to take the JSON serialization into account (#1528)\n  * (docs) fix justification format (#1524)\n  * Add G121 analyzer for unsafe CORS bypass patterns in CrossOriginProtection (#1521)\n  * Add G120 SSA analyzer for unbounded form parsing in HTTP handlers (#1520)\n  * Add G119 analyzer for unsafe redirect header propagation in CheckRedirect callbacks (#1519)\n  * Fix G115 false positives and negatives (Issue #1501) (#1518)\n  * chore(deps): update all dependencies (#1517)\n  * Add G118 SSA analyzer for context propagation failures that can cause goroutine/resource leaks (#1516)\n  * Add G113: Detect HTTP Request Smuggling via conflicting headers (CVE-2025-22891, CWE-444) (#1515)\n  * Add G408: SSH PublicKeyCallback Authentication Bypass Analyzer (#1513)\n  * Add more unit tests to improve coverage (#1512)\n  * Improve test coverage in various areas (#1511)\n  * Imprve the test coverage (#1510)\n  * Fix incorrect detection of fixed iv in G407 (#1509)\n  * Add support for go 1.26.x and removed support for go 1.24.x (#1508)\n  * Fix the sonar report to follow the latest schema (#1507)\n  * fix: broken taint analysis causing false positives (#1506)\n  * fix: panic on float constants in overflow analyzer (#1505)\n  * fix: panic when scanning multi-module repos from root (#1504)\n  * fix: G602 false positive for array element access (#1499)\n  * Update gosec to version v2.23.0 in the Github action (#1496)\n\n- Update to version 2.23.0:\n  * feat: Support for adding taint analysis engine (#1486)\n  * chore(deps): update all dependencies (#1494)\n  * chore(deps): update all dependencies (#1494)\n  * chore(deps): update all dependencies (#1488)\n  *  Fix G602 analyzer panic that kills gosec process (#1491)\n  * update go version to 1.25.7 (#1492)\n  * Fix URL regexp and remove redundant Google regex patterns (#1485)\n  * feat: implement global cache usage in rules (#1480)\n  * chore(deps): update module google.golang.org/genai to v1.43.0 (#1484)\n  * refactor: optimize nosec parsing and reduce allocations (#1478)\n  * Fix SARIF artifactChanges null validation error (#1483)\n  * feat: optimize GetCallInfo with per-package sync.Pool caching (#1481)\n  * feat: implement entropy pre-filtering to optimize secret detection (#1479)\n  * feat: ensure GoVersion is cached using sync.Once (#1477)\n  * Fix #1240: nosec comments now work with trailing open brackets (#1475)\n  * Debug Build Profiling Support: Code improvement suggestions for PR#1471 (#1476)\n  * Update the go version to 1.25.6 and 1.24.12 (#1474)\n  * G115: Enhance RangeAnalyzer with constant propagation and chained arithmetic support (#1470)\n  * chore(deps): update all dependencies (#1473)\n  * feat: support path-based rule exclusions via exclude-rules (#1465)\n  * Optimize analyzer with parallel package processing (#1466)\n  * feat: add goanalysis package for nogo (#1449)\n  * Refactor Analyzers: Unify Range Logic & Optimize Allocations (#1464)\n  * Optimize G115, G602, G407 analyzers to reduce allocations and memory (#1463)\n  * refactor(g115): improve coverage (#1462)\n  * Refine G407 to improve detection and coverage of hardcoded nonces (#1460)\n  * chore(deps): update all dependencies (#1461)\n  * Refactor rules to use callListRule base structure (#1458)\n  * feat(slice): enhance slice bounds analysis with dynamic bounds handling (#1457)\n  * remove deprecated ast.Object (#1455)\n  * feat(sql): enhance SQL injection detection with improved string concatenation checks (#1454)\n  * feat(rules): enhance subprocess variable checks (#1453)\n  * feat(resolve): enhance TryResolve to handle KeyValueExpr, IndexExpr, and SliceExpr (#1452)\n  * feat: add secrets serialization G117 (#1451)\n  * feat(rules): add support for detecting high entropy strings in composite literals (#1447)\n  * whitelist crypto/rand Read from error checks (#1446)\n  * chore(deps): update all dependencies (#1443)\n  * Improve slice bound check (#1442)\n  * docs: add documentation for using gosec with private modules (#1441)\n  * chore(deps): update all dependencies (#1440)\n  * docs: add G116 rule description to README (#1439)\n  * Update GitHub action to gosec 2.22.11 (#1438)\n\n- Update to version 2.22.11:\n  * feature: add rule for trojan source (#1431)\n  * feat(ai): add OpenAI and custom API provider support (#1424)\n  * chore: Migrate from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#1437)\n  * chore(deps): update module google.golang.org/genai to v1.37.0 (#1435)\n  * refactor: simplify report functions in main.go (#1434)\n  * Update go to 1.25.5 and 1.24.11 in CI (#1433)\n  * chore(deps): update all dependencies (#1425)\n  * feat(ai): add support for latest Claude models and update provider flags (#1423)\n  * Bump golang.org/x/crypto from 0.43.0 to 0.45.0 (#1427)\n  * chore(deps): update module golang.org/x/crypto to v0.45.0 [security] (#1428)\n  * fix: correct schema with temporary placeholder (#1418)\n  * perf: skip SSA analysis if no analyzers are loaded (#1419)\n  * test: add sarif validation (#1417)\n  * chore(deps): update all dependencies (#1421)\n  * Update go to version 1.25.4 and 1.24.10 in CI (#1415)\n  * fix: build tag parsing. (#1413)\n  * chore(deps): update all dependencies (#1411)\n  * chore(deps): update all dependencies (#1409)\n  * chore(deps): update all dependencies (#1408)\n  * Update gosec to version v2.22.10 in the github action (#1405)\n\n- Update to version 2.22.10:\n  * Update go to version 1.25.3 and 1.24.9 in CI (#1404)\n  * chore(deps): update all dependencies (#1402)\n  * Update go to version 1.25.2 and 2.24.8 in CI (#1401)\n  * chore(deps): update all dependencies (#1399)\n  * check nil slices, partially check bounds (#1396)\n  * Remove unused target from the makefile\n  * Use the ginkgo command install by the dependencies\n  * Keep the go module at 1.24 version for compatibility reasons\n  * Remove manual test deps\n  * fix: text must be supplied when markdown is used\n  * fix: improve error message of CheckAnalyzers\n  * fix: log panic on SSA\n  * chore(deps): update all dependencies\n  * Update gosec to version v.22.9 in the github action\n\n- Update to version 2.22.9:\n  * Update cosign to v2.6.0 and go in the CI to latest version\n  * fix(autofix): unnecessary conversion\n  * feat(autofix): update gemini sdk and add anthropic claude\n  * feat(G304): add os.Root remediation hint (Autofix) when Go \u003e= 1.24\n  * chore(deps): update all dependencies\n  * refactor(G304): remove unused trackJoin helper; no functional change\n  * style: gofmt rules/readfile.go\n  * test(g304): add samples for var perm and var flag with cleaned path\\n\\n- Ensure G304 does not fire when only non-path args (flag/perm) are variables\\n- Both samples use filepath.Clean on the path arg\\n- Rules suite remains green (42 passed)\n  * rules(G304): analyze only path arg; ignore flag/perm vars; track Clean and safe Join; fix nil-context panic\\n\\n- Limit G304 checks to first arg (path) for os.Open/OpenFile/ReadFile, avoiding false positives when flag/perm are variables\\n- Track filepath.Clean so cleaned identifiers are treated as safe\\n- Consider safe joins: filepath.Join(const|resolvedBase, Clean(var)|cleanedIdent)\\n- Record Join(...) assigned to identifiers and allow if later cleaned\\n- Fix panic by passing non-nil context in trackJoinAssignStmt\\n- All rules tests: 42 passed\n  * rules(G202): detect SQL concat in ValueSpec declarations; add test sample\\n\\n- Handle var query string = 'SELECT ...' + user style declarations\\n- Reuse existing binary expr detection on ValueSpec.Values\\n- Add postgres sample mirroring issue #1309 report\\n- Rules tests: 42 passed\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * Update gosec version to v2.22.8 in the Github action\n\n- Update to version 2.22.8:\n  * Add support for go version 1.25.0\n  * Update go version in CI to 1.24.6 and 1.23.12\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * Update github action to release v2.22.7\n\n- Update to version 2.22.7:\n  * Fix crash in hardcoded_nonce analyzer\n  * Update go action to use release v2.22.6\n  * Update go version to 1.24.5 and 1.23.11 in the CI\n  * chore(deps): update module google.golang.org/api to v0.242.0\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * chore(deps): update all dependencies\n  * Do not allow dashes in file names\n  * Update gosec to version 2.22.5 in Github action\n\n- Update to version 2.22.5:\n  * Switch back go.mod to minimum 1.23.0\n  * Update dependencies\n  * Update go version 1.24.4 and 1.23.10 in CI\n  * chore(deps): update all dependencies\n  * G201/G202: add checks for injection into sql.Conn methods\n  * chore(deps): update module google.golang.org/api to v0.235.0\n  * chore(deps): update module google.golang.org/api to v0.234.0\n  * chore(deps): update module google.golang.org/api to v0.233.0\n  * chore(deps): update module google.golang.org/api to v0.232.0\n\n- Switch vendor from gz to xz for consistency\n\n- Switch from version to revision in _service\n\n- Update to version 2.22.4:\n  * Update to go version 1.24.3 and 1.23.9\n  * update: updated the build command to include version metadata\n  * chore(deps): update all dependencies\n  * Update the AI provider API key value when provided as an argument\n  * chore(deps): update module google.golang.org/api to v0.230.0\n  * chore(deps): update module google.golang.org/api to v0.229.0\n  * chore(deps): update all dependencies\n  * Comment the reason why the file can be nil when an issue is created\n  * Handle nil file when creating a new issue\n  * chore(deps): update all dependencies (#1333)\n\n- Update to version 2.22.3:\n  * Update version in 'action.yml' to 2.22.3 (anticipating next version (#1332)\n  * Update go version to 1.24.2 and 1.23.8 (#1331)\n  * remove G113. It only affects old/unsupported versions of Go (#1328)\n  * chore(deps): update all dependencies (#1325)\n  * Add SSOJet (#1320)\n  * chore(deps): update all dependencies (#1319)\n  * Update the integrity sha for babel dependency in html report (#1316)\n  * Add support for `//gosec:disable` directive (#1314)\n  * chore(deps): update all dependencies (#1315)\n\n- Update to version 2.22.2:\n  * Update to go version 1.24.1 and 1.23.7 (#1313)\n  * chore(deps): update all dependencies (#1310)\n  * chore(deps): update all dependencies (#1308)\n  * Update gosec version in the GitHub action to v2.22.1 (#1307)\n  * chore(deps): update module google.golang.org/api to v0.221.0 (#1305)\n\n- Update to version 2.22.1:\n  * Update cosign to v2.4.2 (#1303)\n  * Add support for go 1.24 and phased out support for go 1.22 (#1302)\n  * chore(deps): update all dependencies (#1300)\n  * Update to go version 1.23.6 and 1.22.12 (#1299)\n  * chore(deps): update module google.golang.org/api to v0.219.0 (#1296)\n  * chore(deps): update module google.golang.org/api to v0.218.0 (#1294)\n  * Add test to conver unit parssing for G115 rule (#1293)\n  * Update to go version 1.23.5 and 1.22.11 (#1291)\n  * chore(deps): update all dependencies (#1290)\n  * Update gosec in github action to 2.22.0 (#1286)\n","modified":"2026-04-22T18:26:34.738030Z","published":"2026-04-14T16:34:51Z","related":["CVE-2025-22891"],"upstream":["CVE-2025-22891"],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22891"}],"affected":[{"package":{"name":"gosec","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gosec&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.25.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gosec":"2.25.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20579-1.json"}}],"schema_version":"1.7.5"}