Skip to content

feat(go): add rtk govulncheck filter - #4508

Open
dDan4a wants to merge 1 commit into
rtk-ai:developfrom
dDan4a:feat/govulncheck
Open

dDan4a wants to merge 1 commit into
rtk-ai:developfrom
dDan4a:feat/govulncheck

Conversation

@dDan4a

@dDan4a dDan4a commented Oct 10, 2026

Copy link
Copy Markdown

Summary

Part of #1990 (Go ecosystem coverage), govulncheck item.

  • New rtk govulncheck. It runs govulncheck with -format json and reports only symbol-level findings, meaning vulnerable code that your code actually calls. Findings are grouped by module, and each module shows the highest fixed version as an upgrade to ... target. Every vulnerability keeps its first call site in the same form as text mode (main.go:11:44 vulnsample.main calls language.ParseAcceptLanguage); additional call sites are collapsed into a count. Package- and module-level findings become a single count line, and that line points to rtk proxy govulncheck -show verbose for the details.

  • Exit code: text mode exits 3 when the code is affected, but JSON mode always exits 0. rtk restores the 3, so gates and agents that check $? keep working.

  • Failed scans: when there is no go.mod, a build error or no network, stdout holds only the config message and the real error is on stderr. In that case rtk prints no summary and forwards stderr. Without this, a partial stream would produce a misleading "no vulnerabilities".

  • The following invocations pass through unchanged:

    • -json, -format;
    • -show, -scan, -mode (they change what "affected" means);
    • -version, -h.

    Flags are classified with arg_tokenizer using Dialect::GoFlag. This is its first in-tree caller, so the #[allow(dead_code)] on it is removed.

  • Adds a hook rewrite rule (govulncheck → rtk govulncheck) and doc table entries.

The fixture is a real govulncheck -format json stream from a sample module (golang.org/x/text@v0.3.7, gopkg.in/yaml.v2@v2.2.2). It was trimmed to the findings plus their OSV records, and those records were reduced to id/summary/details/aliases: 21 KB instead of 596 KB.

Measurements

Same sample module: 4 vulnerabilities called, 1 more in imported packages, 14 more in required modules.

Output Bytes
govulncheck -format json ./... (what rtk parses) 596,576
govulncheck ./... (default text) 1,656
rtk govulncheck ./... 824

Test plan

  • cargo fmt --all && cargo clippy --all-targets && cargo test --all: 4310 passed, clippy clean
  • Manual testing with govulncheck v1.8.0 and Go 1.27.1:
    • vulnerable module: grouped report, highest fix (v2.2.8 across three yaml.v2 vulns), call sites match text mode, exit code 3;
    • clean module: "no vulnerabilities affect your code" plus the not-called counts, exit code 0;
    • directory without go.mod: govulncheck's own error is shown, no bogus summary, exit code 1;
    • -show verbose passes through untouched;
    • rtk rewrite "govulncheck -test ./..." → rtk govulncheck -test ./....

This touches the same registration lists as #4495 (gotestsum: main.rs, discover/rules.rs, the producer-safe list and the doc tables). Whichever PR merges second will need a trivial rebase, and I'll handle it.

Targets develop.

@rtk-wshm-sync-bot

Copy link
Copy Markdown

wshm · Automated triage by AI

📊 Automated PR Analysis

✨ Type feature
🟡 Risk medium

Summary

Adds a new rtk govulncheck subcommand that runs govulncheck -format json and filters the output to symbol-level findings (vulnerabilities actually called by the code), grouping by module with the highest fix version and collapsing extra call sites into counts. It restores the exit code 3 that JSON mode normally suppresses, passes through flags that change output format or scan semantics, forwards stderr untouched on failed scans, and adds a hook rewrite rule plus documentation entries.

Review Checklist

  • Tests present
  • Breaking change
  • Docs updated

Analyzed automatically by wshm · This is an automated analysis, not a human review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant