mirror of
https://github.com/securego/gosec.git
synced 2026-06-20 00:15:59 +02:00
1.3 KiB
1.3 KiB
Fix a gosec bug from a GitHub issue
Use this command to fix a bug described in a GitHub issue.
Required input
Provide the GitHub issue URL (and optionally gosec version, Go version, OS/environment, extra notes):
$ARGUMENTS
Execution workflow
- Review the GitHub issue thoroughly and extract the problem statement, reproduction hints, expected behavior, and actual behavior.
- Try to reproduce the issue against the current
masterversion of gosec. - Analyze the codebase and isolate the root cause.
- Produce a detailed, minimal fix plan and stop. Ask for confirmation before changing code.
After confirmation, implement end-to-end:
- Keep the fix small and isolated to the issue scope.
- Follow good design principles and idiomatic Go.
- Add tests for both positive and negative cases.
- When a code sample is appropriate, add or update a sample in
testutils/in the relevant rule sample file. - Validate the result:
- Build succeeds
- Relevant tests pass
golangci-linthas no warnings in changed codegosecCLI run on a sample confirms the issue is fixed
Output requirements
- First response must only contain:
- Reproduction status on
master(or clear blocker) - Root cause analysis
- Detailed fix plan
- Confirmation request
- Reproduction status on
- Do not implement any code changes until confirmation is provided.