Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions pkg/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,7 @@ func CreateTLSConfig() *tls.Config {
sepCaFiles := strings.Split(CaCertPaths, ",")
for _, f := range sepCaFiles {
// Read in the cert file
// #nosec G304 -- f is a CA cert file path supplied by the user via --caCertPaths flag; reading it is the intended behavior.
certs, err := os.ReadFile(f)
if err != nil {
fmt.Println("Unable to read cert file from CaCertPaths: " + f)
Expand Down
4 changes: 2 additions & 2 deletions pkg/config/localconfig.go
Original file line number Diff line number Diff line change
Expand Up @@ -171,7 +171,7 @@ func ValidateLocalConfig(config LocalConfig) error {

// WriteLocalConfig writes a new local configuration file.
func WriteLocalConfig(config LocalConfig, configPath string) error {
err := os.MkdirAll(filepath.Dir(configPath), os.ModePerm)
err := os.MkdirAll(filepath.Dir(configPath), 0750) // G301: Use restrictive permissions instead of os.ModePerm (0777)
if err != nil {
return err
}
Expand Down Expand Up @@ -423,7 +423,7 @@ func ReadLocalWatchConfig(path string) (*WatchConfig, error) {

// WriteLocalWatchConfig writes a new local watch configuration file.
func WriteLocalWatchConfig(config WatchConfig, cfgPath string) error {
err := os.MkdirAll(filepath.Dir(cfgPath), os.ModePerm)
err := os.MkdirAll(filepath.Dir(cfgPath), 0750) // G301: Use restrictive permissions instead of os.ModePerm (0777)
if err != nil {
return err
}
Expand Down
1 change: 1 addition & 0 deletions pkg/connectors/microcks_client.go
Original file line number Diff line number Diff line change
Expand Up @@ -632,6 +632,7 @@ func (c *microcksClient) GetFullTestResult(testResultID string) (*TestResult, er

func (c *microcksClient) UploadArtifact(specificationFilePath string, mainArtifact bool) (string, error) {
// Ensure file exists on fs.
// #nosec G304 -- specificationFilePath is an artifact path provided explicitly by the CLI user; not a web-facing input.
file, err := os.Open(specificationFilePath)
if err != nil {
return "", errors.Wrap(errors.KindUsage, fmt.Errorf("cannot read artifact %q: %w", specificationFilePath, err))
Expand Down
3 changes: 2 additions & 1 deletion pkg/output/github_actions_formatter.go
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,8 @@ func writeStepSummary(r *connectors.TestResult) error {
}
b.WriteString("\n")

file, err := os.OpenFile(path, os.O_APPEND|os.O_WRONLY|os.O_CREATE, 0o644)
// #nosec G703,G304 -- path is the GITHUB_OUTPUT env var set by the Actions runner; it is a trusted system value, not user web input.
file, err := os.OpenFile(path, os.O_APPEND|os.O_WRONLY|os.O_CREATE, 0o600) // G302: restrictive permissions
if err != nil {
return err
}
Expand Down
1 change: 1 addition & 0 deletions pkg/output/openapi_linemap.go
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ func openAPIOperationLine(specPath, operationName string) int {
return 0
}

// #nosec G304 -- specPath is a local file path explicitly provided by the CLI user; not a web input.
data, err := os.ReadFile(specPath)
if err != nil {
return 0
Expand Down
1 change: 1 addition & 0 deletions pkg/util/util.go
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ import (
// UnmarshalLocalFile retrieves JSON or YAML from a file on disk.
// The caller is responsible for checking error return values.
func UnmarshalLocalFile(path string, obj interface{}) error {
// #nosec G304 -- path is provided by the CLI user or local config; directory traversal is not a concern for a local CLI tool.
data, err := os.ReadFile(path)
if err == nil {
err = unmarshalObject(data, obj)
Expand Down
Loading