Skip to content

fix(explain): document the route lookup flagged by gosec G704 - #19

Merged
NycolazSec merged 1 commit into
mainfrom
feat/exposure-explain
Oct 10, 2026
Merged

NycolazSec merged 1 commit into
mainfrom
feat/exposure-explain

Conversation

@NycolazSec

Copy link
Copy Markdown
Owner

Summary

main is red since #18: gosec's G704 (SSRF taint) flags the net.Dial("udp", ...) in tunnelInterfaceFor. It is a route lookup only — connecting a UDP socket sends nothing — and the address is the host the operator asked to probe. Annotated with #nosec G704 and the justification, like the repository's other exceptions.

Checklist

  • gofmt -l . produces no output
  • go vet ./... passes
  • The CI's gosec image (same digest) reports 0 issues locally

Test plan

Ran ghcr.io/securego/gosec@sha256:a6cd2f30… with the CI's arguments on this branch: 0 issues.

tunnelInterfaceFor connects a UDP socket only to learn which interface
the kernel would route the target through; nothing is sent, and the
address is the host the operator asked to probe. Annotate it like the
repository's other justified exceptions.
@NycolazSec NycolazSec mentioned this pull request Oct 10, 2026
1 task done
@NycolazSec
NycolazSec merged commit 77cb79d into main Oct 10, 2026
5 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 10, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant