Skip to content

False vulnerabilities being reported by v2.17.0 #1001

@revanth844

Description

@revanth844

Summary

Latest release is reporting Severity-HIGH false-positives.

Steps to reproduce the behavior

package main

func main() {
        usersPerAccountLimit := "users_per_account_limit"
        _ = usersPerAccountLimit
}

gosec version

v2.17.0

Go version (output of 'go version')

go1.19.9

Operating system / Environment

linux/amd64

Expected behavior

gosec scan to pass

Actual behavior

G101 (CWE-798): Potential hardcoded credentials (Confidence: LOW, Severity: HIGH)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions