A project devoted to secure programming in the Go language. Licensed under the Apache License, Version 2.0 (the "License"). You may not use this file except in compliance with the License. You can integrate third-party code analysis tools with GitHub code scanning by uploading data as SARIF files. The workflow shows an example of running the gosec as a step in a GitHub action workflow that outputs the results.sarif file. The workflow then uploads the results.sarif file to GitHub using the upload-serif action. Gosec can be configured to only run a subset of rules, to exclude certain file paths, and produce reports in different formats. By default, all rules will be run against the supplied input files.

Features

  • CI Installation
  • You can run gosec as a GitHub action
  • Integrate with code scanning
  • Gosec can be configured to only run a subset of rules
  • Exclude certain file paths
  • Produce reports in different formats

Project Samples

Project Activity

See All Activity >

License

Apache License V2.0

Follow gosec

gosec Web Site

Other Useful Business Software
Custom VMs From 1 to 96 vCPUs With 99.95% Uptime Icon
Custom VMs From 1 to 96 vCPUs With 99.95% Uptime

General-purpose, compute-optimized, or GPU/TPU-accelerated. Built to your exact specs.

Live migration and automatic failover keep workloads online through maintenance. One free e2-micro VM every month.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of gosec!

Additional Project Details

Programming Language

Go

Related Categories

Go Static Code Analysis Tool

Registered

2023-03-30