Skip to content

pilotctl: justify the five gosec findings introduced by #490 - #502

Merged
TeoSlayer merged 1 commit into
mainfrom
chore/gosec-annotations-490
Oct 7, 2026
Merged

TeoSlayer merged 1 commit into
mainfrom
chore/gosec-annotations-490

Conversation

@TeoSlayer

Copy link
Copy Markdown
Collaborator

Pull Request

Summary

#490 merged with the (non-gating) gosec check reporting 5 new G703 "path traversal via taint" alerts in cmd/pilotctl/appstore.go. None is exploitable; this annotates them with the reason, as the surrounding code does, so the scan is back to its baseline.

Changes

  • os.RemoveAll(bundleDir) in install: for a catalogue install bundleDir is the os.MkdirTemp directory fetchAndUnpackBundle created, never a caller-supplied path.
  • Four os.Stat calls in appstore call / waitForAppSocket: stats of fixed names (app.sock, manifest.json, .suspended) under the app directory the operator named; nothing is read or written.

No behaviour change.

Test Plan

  • go build ./cmd/pilotctl/
  • gosec -include=G703 ./cmd/pilotctl/: the five lines are no longer reported; the remaining findings are pre-existing

🤖 Generated with Claude Code

gosec's taint analysis flagged the unpack-directory removal and the app
socket/manifest/.suspended stats added in #490. The removal only ever
targets the os.MkdirTemp directory of a catalogue install; the others are
stats of fixed names under the app directory the operator named. Annotate
them the way the surrounding code does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@TeoSlayer
TeoSlayer force-pushed the chore/gosec-annotations-490 branch from 56bf517 to 315802a Compare October 7, 2026 13:09
@TeoSlayer
TeoSlayer merged commit e5b8c25 into main Oct 7, 2026
15 checks passed
@TeoSlayer
TeoSlayer deleted the chore/gosec-annotations-490 branch October 7, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant