Repository navigation
Conversation
📊 Automated PR Analysis
SummaryAdds a new Review Checklist
Analyzed automatically by wshm · This is an automated analysis, not a human review. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Part of #1990 (Go ecosystem coverage), govulncheck item.
New
rtk govulncheck. It runs govulncheck with-format jsonand reports only symbol-level findings, meaning vulnerable code that your code actually calls. Findings are grouped by module, and each module shows the highest fixed version as anupgrade to ...target. Every vulnerability keeps its first call site in the same form as text mode (main.go:11:44 vulnsample.main calls language.ParseAcceptLanguage); additional call sites are collapsed into a count. Package- and module-level findings become a single count line, and that line points tortk proxy govulncheck -show verbosefor the details.Exit code: text mode exits
3when the code is affected, but JSON mode always exits0. rtk restores the3, so gates and agents that check$?keep working.Failed scans: when there is no
go.mod, a build error or no network, stdout holds only theconfigmessage and the real error is on stderr. In that case rtk prints no summary and forwards stderr. Without this, a partial stream would produce a misleading "no vulnerabilities".The following invocations pass through unchanged:
-json,-format;-show,-scan,-mode(they change what "affected" means);-version,-h.Flags are classified with
arg_tokenizerusingDialect::GoFlag. This is its first in-tree caller, so the#[allow(dead_code)]on it is removed.Adds a hook rewrite rule (
govulncheck→rtk govulncheck) and doc table entries.The fixture is a real
govulncheck -format jsonstream from a sample module (golang.org/x/text@v0.3.7,gopkg.in/yaml.v2@v2.2.2). It was trimmed to the findings plus their OSV records, and those records were reduced toid/summary/details/aliases: 21 KB instead of 596 KB.Measurements
Same sample module: 4 vulnerabilities called, 1 more in imported packages, 14 more in required modules.
govulncheck -format json ./...(what rtk parses)govulncheck ./...(default text)rtk govulncheck ./...Test plan
cargo fmt --all && cargo clippy --all-targets && cargo test --all: 4310 passed, clippy cleanv2.2.8across three yaml.v2 vulns), call sites match text mode, exit code 3;go.mod: govulncheck's own error is shown, no bogus summary, exit code 1;-show verbosepasses through untouched;rtk rewrite "govulncheck -test ./..."→rtk govulncheck -test ./....This touches the same registration lists as #4495 (gotestsum:
main.rs,discover/rules.rs, the producer-safe list and the doc tables). Whichever PR merges second will need a trivial rebase, and I'll handle it.