diff --git a/pkg/config/config.go b/pkg/config/config.go index dc165a5e..72c8eb7a 100644 --- a/pkg/config/config.go +++ b/pkg/config/config.go @@ -58,6 +58,7 @@ func CreateTLSConfig() *tls.Config { sepCaFiles := strings.Split(CaCertPaths, ",") for _, f := range sepCaFiles { // Read in the cert file + // #nosec G304 -- f is a CA cert file path supplied by the user via --caCertPaths flag; reading it is the intended behavior. certs, err := os.ReadFile(f) if err != nil { fmt.Println("Unable to read cert file from CaCertPaths: " + f) diff --git a/pkg/config/localconfig.go b/pkg/config/localconfig.go index b930704d..2aaa1b13 100644 --- a/pkg/config/localconfig.go +++ b/pkg/config/localconfig.go @@ -171,7 +171,7 @@ func ValidateLocalConfig(config LocalConfig) error { // WriteLocalConfig writes a new local configuration file. func WriteLocalConfig(config LocalConfig, configPath string) error { - err := os.MkdirAll(filepath.Dir(configPath), os.ModePerm) + err := os.MkdirAll(filepath.Dir(configPath), 0750) // G301: Use restrictive permissions instead of os.ModePerm (0777) if err != nil { return err } @@ -423,7 +423,7 @@ func ReadLocalWatchConfig(path string) (*WatchConfig, error) { // WriteLocalWatchConfig writes a new local watch configuration file. func WriteLocalWatchConfig(config WatchConfig, cfgPath string) error { - err := os.MkdirAll(filepath.Dir(cfgPath), os.ModePerm) + err := os.MkdirAll(filepath.Dir(cfgPath), 0750) // G301: Use restrictive permissions instead of os.ModePerm (0777) if err != nil { return err } diff --git a/pkg/connectors/microcks_client.go b/pkg/connectors/microcks_client.go index 9dbf58d6..3e121ae0 100644 --- a/pkg/connectors/microcks_client.go +++ b/pkg/connectors/microcks_client.go @@ -632,6 +632,7 @@ func (c *microcksClient) GetFullTestResult(testResultID string) (*TestResult, er func (c *microcksClient) UploadArtifact(specificationFilePath string, mainArtifact bool) (string, error) { // Ensure file exists on fs. + // #nosec G304 -- specificationFilePath is an artifact path provided explicitly by the CLI user; not a web-facing input. file, err := os.Open(specificationFilePath) if err != nil { return "", errors.Wrap(errors.KindUsage, fmt.Errorf("cannot read artifact %q: %w", specificationFilePath, err)) diff --git a/pkg/output/github_actions_formatter.go b/pkg/output/github_actions_formatter.go index 017863aa..4bdaae87 100644 --- a/pkg/output/github_actions_formatter.go +++ b/pkg/output/github_actions_formatter.go @@ -108,7 +108,8 @@ func writeStepSummary(r *connectors.TestResult) error { } b.WriteString("\n") - file, err := os.OpenFile(path, os.O_APPEND|os.O_WRONLY|os.O_CREATE, 0o644) + // #nosec G703,G304 -- path is the GITHUB_OUTPUT env var set by the Actions runner; it is a trusted system value, not user web input. + file, err := os.OpenFile(path, os.O_APPEND|os.O_WRONLY|os.O_CREATE, 0o600) // G302: restrictive permissions if err != nil { return err } diff --git a/pkg/output/openapi_linemap.go b/pkg/output/openapi_linemap.go index be25d599..8acfbc34 100644 --- a/pkg/output/openapi_linemap.go +++ b/pkg/output/openapi_linemap.go @@ -33,6 +33,7 @@ func openAPIOperationLine(specPath, operationName string) int { return 0 } + // #nosec G304 -- specPath is a local file path explicitly provided by the CLI user; not a web input. data, err := os.ReadFile(specPath) if err != nil { return 0 diff --git a/pkg/util/util.go b/pkg/util/util.go index 8b1f0859..0536527c 100644 --- a/pkg/util/util.go +++ b/pkg/util/util.go @@ -25,6 +25,7 @@ import ( // UnmarshalLocalFile retrieves JSON or YAML from a file on disk. // The caller is responsible for checking error return values. func UnmarshalLocalFile(path string, obj interface{}) error { + // #nosec G304 -- path is provided by the CLI user or local config; directory traversal is not a concern for a local CLI tool. data, err := os.ReadFile(path) if err == nil { err = unmarshalObject(data, obj)