Skip to content

fix: safely handle unhandled errors in watcher and health checks (CWE-703) - #558

Merged
Harsh4902 merged 2 commits into
microcks:masterfrom
Vaishnav88sk:fix/security-unhandled-errors
Sep 30, 2026
Merged

Harsh4902 merged 2 commits into
microcks:masterfrom
Vaishnav88sk:fix/security-unhandled-errors

Conversation

@Vaishnav88sk

Copy link
Copy Markdown
Contributor

Description

This PR resolves warnings regarding unhandled errors identified by the gosec SAST scanner.

Security Fixes (CWE-703):

  • G104: The scanner flagged two instances where returned errors were silently dropped.
    1. In watchManager.go, we now explicitly check and log a warning if removing a stale file watcher fails.
    2. In start.go, the resp.Body.Close() error in the health-check polling loop is now explicitly ignored using the blank identifier (_ =) to indicate this is an intentional, non-fatal discard.

How to test

  1. Run gosec -include=G104 ./cmd/... ./pkg/watcher/... and verify 0 issues are found.

…104)

Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>
Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>

@Harsh4902 Harsh4902 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Harsh4902
Harsh4902 merged commit e54dc47 into microcks:master Sep 30, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
Build — aab1a838 Deployed Sep 29, 2026 by Vaishnav88sk via build-verify-package #750
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants