Skip to content

golangci-lint

golangci-lint #8661

Triggered via schedule March 13, 2026 05:20
Status Failure
Total duration 3m 29s
Artifacts

golangci-lint.yml

on: schedule
Fit to window
Zoom out
Zoom in

Annotations

10 errors
golangci-lint: internal/cmd/cli/analyze.go#L209
directive `//nolint:gosec // G705 false positive: w is a CLI stdout writer, not an HTTP ResponseWriter` is unused for linter "gosec" (nolintlint)
golangci-lint: internal/cmd/agent/register/register.go#L304
directive `//nolint:gosec // G704 false positive: URL is the Kubernetes API server from admin-configured kubeconfig` is unused for linter "gosec" (nolintlint)
golangci-lint: internal/bundlereader/loaddirectory.go#L435
directive `//nolint:gosec // G703 false positive: path comes from os.CreateTemp, not user-controlled data` is unused for linter "gosec" (nolintlint)
golangci-lint: internal/bundlereader/charturl.go#L165
directive `//nolint:gosec // G704 false positive: URL is the user-configured Helm chart repository` is unused for linter "gosec" (nolintlint)
golangci-lint: internal/bundlereader/auth.go#L18
directive `//nolint:gosec // G117 false positive: Password is an intentional field in the Helm chart auth config` is unused for linter "gosec" (nolintlint)
golangci-lint: cmd/docs/generate-cli-docs.go#L156
directive `//nolint:gosec // G705 false positive: output goes to stdout, not an HTTP response writer` is unused for linter "gosec" (nolintlint)
golangci-lint: pkg/webhook/webhook_test.go#L877
net/http/httptest.NewRequest must not be called. use net/http/httptest.NewRequestWithContext (noctx)
golangci-lint: pkg/webhook/webhook.go#L203
G705: XSS via taint analysis (gosec)
golangci-lint: internal/cmd/controller/imagescan/update/filereader.go#L94
G122: Filesystem operation in filepath.Walk/WalkDir callback uses race-prone path; consider root-scoped APIs (e.g. os.Root) to prevent symlink TOCTOU traversal (gosec)
golangci-lint: internal/bundlereader/loaddirectory.go#L322
G122: Filesystem operation in filepath.Walk/WalkDir callback uses race-prone path; consider root-scoped APIs (e.g. os.Root) to prevent symlink TOCTOU traversal (gosec)