Skip to content

chore: update github.com/securego/gosec/v2 from v2.24.7 to v2.25.0#22465

Merged
pelikhan merged 2 commits intomainfrom
copilot/update-gosec-v2-24-7-to-v2-25-0
Mar 23, 2026
Merged

chore: update github.com/securego/gosec/v2 from v2.24.7 to v2.25.0#22465
pelikhan merged 2 commits intomainfrom
copilot/update-gosec-v2-24-7-to-v2-25-0

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 23, 2026

Minor version bump of gosec adding three new detection rules (G124: insecure HTTP cookie config, G708: server-side template injection via text/template, G709: unsafe deserialization). Includes transitive bumps to openai-go/v3, golang.org/x/net, golang.org/x/tools, and google.golang.org/genai.

No new gosec findings in the codebase — none of the new rules (G124, G708, G709) flag existing code.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/graphql
    • Triggering command: /usr/bin/gh /usr/bin/gh api graphql -f query=query($owner: String!, $name: String!) { repository(owner: $owner, name: $name) { hasDiscussionsEnabled } } -f owner=github -f name=gh-aw GO111MODULE 64/pkg/tool/linu--show-toplevel git rev-�� --show-toplevel 64/pkg/tool/linux_amd64/vet /usr/bin/git 9907727/b215/_pkgit kmbI/DF4yalWSRBzrev-parse .cfg git (http block)
    • Triggering command: /usr/bin/gh /usr/bin/gh api graphql -f query=query($owner: String!, $name: String!) { repository(owner: $owner, name: $name) { hasDiscussionsEnabled } } -f owner=github -f name=gh-aw **/*.cjs /home/REDACTED/wor--show-toplevel git rev-�� --show-toplevel sh /usr/bin/git "prettier" --wrigit git 64/pkg/tool/linu--show-toplevel git (http block)
  • https://api.github.com/orgs/test-owner/actions/secrets
    • Triggering command: /usr/bin/gh gh api /orgs/test-owner/actions/secrets --jq .secrets[].name -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh api /orgs/test-owner/actions/secrets --jq .secrets[].name ignore-path ../../../.prettierignore /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linuf() { test "$1" = get && echo "****** /usr/bin/git bility_SameInputsh /tmp/go-build384-c /usr/bin/git git rev-�� --show-toplevel git /usr/bin/git /tmp/gh-aw-test-node rev-parse /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh api /orgs/test-owner/actions/secrets --jq .secrets[].name --show-toplevel gh ules/.bin/sh download 2 /usr/bin/git git rev-�� mpiledOutput3147545627/001 git /usr/bin/git --show-toplevel x_amd64/link /usr/bin/git git (http block)
  • https://api.github.com/repos/actions/ai-inference/git/ref/tags/v1
    • Triggering command: /usr/bin/gh gh api /repos/actions/ai-inference/git/ref/tags/v1 --jq .object.sha user.name Test User /usr/bin/git -json GO111MODULE x_amd64/vet git rev-�� --show-toplevel x_amd64/vet /usr/bin/git ub/workflows @v1.1.3/ascii/asrev-parse x_amd64/vet /usr/bin/git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/ai-inference/git/ref/tags/v1 --jq .object.sha --show-toplevel git /usr/bin/git --show-toplevel git 0/x64/bin/node git rev-�� --show-toplevel git /opt/hostedtoolcache/node/24.14.0/x64/bin/node SameOutput178961git git e_modules/.bin/s--show-toplevel node (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v3
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v3 --jq .object.sha -bool -buildtags /usr/bin/git -errorsas -ifaceassert -nilfunc git rev-�� --show-toplevel -tests ache/node/24.14.0/x64/bin/node -json GO111MODULE x_amd64/compile git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v3 --jq .object.sha --show-toplevel git 0/x64/bin/node ub/workflows git /usr/bin/wc bash t-ha�� SameOutput2121835974/001/stability-test.md wc /usr/bin/git ../pkg/workflow/git git 64/bin/go git (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v5
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha ortcfg GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linu--json -c 07/001/test-fron--workflow GOPROXY .cfg GOSUMDB fips140/hkdf 64/bin/go ache/go/1.25.0/x64/pkg/tool/linurev-parse (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha list --json /usr/bin/git --workflow nonexistent-workrev-parse --limit git rev-�� --show-toplevel 64/pkg/tool/linurev-parse s e=false .cfg 64/pkg/tool/linu--show-toplevel infocmp (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha --show-toplevel ache/go/1.25.0/x64/pkg/tool/linuremote.origin.url /usr/bin/git 9907727/b203/impgit -trimpath 64/pkg/tool/linu--show-toplevel git rev-�� --show-toplevel 64/pkg/tool/linux_amd64/compile n-dir/node g_.a -trimpath 7149369/b131/vet--show-toplevel git (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v6
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v6 --jq .object.sha --show-toplevel x_amd64/compile /usr/bin/git with-tools.md GO111MODULE x_amd64/link git chec�� .github/workflows/test.md x_amd64/link /usr/bin/git -json @v1.1.3/internalrev-parse x_amd64/vet git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v6 --jq .object.sha uts.branch x_amd64/compile /usr/bin/git -json GO111MODULE x_amd64/vet git rev-�� --git-dir x_amd64/vet /usr/bin/git -json GO111MODULE x_amd64/vet git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v6 --jq .object.sha --show-toplevel 64/pkg/tool/linux_amd64/vet /usr/bin/ls q6ZV/zBE_EJgyq1cgit ache/go/1.25.0/xrev-parse .cfg ls -alF�� /var/lib/waagent ache/go/1.25.0/x64/pkg/tool/linux_amd64/vet /usr/bin/git /tmp/go-build328git pkg/mod/github.crev-parse .cfg git (http block)
  • https://api.github.com/repos/actions/github-script/git/ref/tags/v8
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha -json GO111MODULE x_amd64/asm GOINSECURE GOMOD GOMODCACHE x_amd64/asm env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env -json age/common.go x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env -json 1.4.1/internal/u-ifaceassert x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
  • https://api.github.com/repos/actions/setup-go/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/v4 --jq .object.sha ue.number -test.v=true /usr/bin/git -test.timeout=10git -test.run=^Test -test.short=true--show-toplevel git -C /tmp/gh-aw-test-runs/20260323-165841-38187/test-1363177092 status /usr/bin/git .github/workflowgit GO111MODULE x_amd64/vet git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/v4 --jq .object.sha --show-toplevel om/owner/repo.git /usr/bin/git */*.json' '!../.git git 64/pkg/tool/linu--show-toplevel git rev-�� --git-dir 64/pkg/tool/linux_amd64/vet /usr/bin/git --show-toplevel git es/.bin/sh git (http block)
  • https://api.github.com/repos/actions/setup-node/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v4 --jq .object.sha test/concurrent-image:v1.0.0 x_amd64/compile /usr/bin/git -template-expresgit GO111MODULE x_amd64/vet git rev-�� --git-dir x_amd64/vet /usr/bin/git -json GO111MODULE x_amd64/vet git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v4 --jq .object.sha = get && echo "******"; }; f get = get && echo "******"; }; f get /usr/bin/git */*.json' '!../.git git /usr/bin/git git conf�� user.name Test User /usr/bin/git --show-toplevel git k/node_modules/.--show-toplevel git (http block)
  • https://api.github.com/repos/actions/upload-artifact/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/upload-artifact/git/ref/tags/v4 --jq .object.sha -unreachable=false /tmp/go-build3847149369/b088/vet.cfg 7149369/b361/vet.cfg go1.25.0 -c=4 -nolocalimports /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet -uns�� -unreachable=false /tmp/go-build3847149369/b239/vet.cfg /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet -json GO111MODULE 64/bin/go /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/upload-artifact/git/ref/tags/v4 --jq .object.sha ace-editor.md origin /usr/bin/git --show-toplevel ache/node/24.14.rev-parse _modules/.bin/sh--show-toplevel git init�� /usr/bin/git gh 7779327/b435/vet.cfg 06/001 --jq /usr/lib/git-cor--show-toplevel /usr/bin/git (http block)
  • https://api.github.com/repos/github/gh-aw-actions/git/ref/tags/v1.0.0
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw-actions/git/ref/tags/v1.0.0 --jq .object.sha 5841-38187/test-1363177092 /tmp/go-build3847149369/b003/vet.cfg 7149369/b382/vet.cfg go1.25.0 -c=4 -nolocalimports /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet -uns�� -unreachable=false /tmp/go-build3847149369/b227/vet.cfg 0/x64/bin/node -json GO111MODULE 64/bin/go 0/x64/bin/node (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw-actions/git/ref/tags/v1.0.0 --jq .object.sha user.name Test User (http block)
  • https://api.github.com/repos/github/gh-aw-actions/git/ref/tags/v1.2.3
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw-actions/git/ref/tags/v1.2.3 --jq .object.sha runs/20260323-165841-38187/test-2044941446/.github/workflows /tmp/go-build3847149369/b071/vet.cfg 7149369/b381/vet.cfg l -c=4 -nolocalimports /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet -uns�� -unreachable=false /tmp/go-build3847149369/b200/vet.cfg 0/x64/bin/node -json GO111MODULE odules/npm/node_--show-toplevel 0/x64/bin/node (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw-actions/git/ref/tags/v1.2.3 --jq .object.sha github.token git /usr/bin/git --show-toplevel git /usr/bin/git git remo�� runs/20260323-170249-44951/test-1081645203/custom/workflows origin /usr/bin/infocmp l git /usr/bin/git infocmp (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/1/artifacts
    • Triggering command: /usr/bin/gh gh run download 1 --dir test-logs/run-1 TAWkEgFot 64/pkg/tool/linux_amd64/vet GOINSECURE cii ode-gyp-bin/sh 64/pkg/tool/linux_amd64/vet env LcYD5F2cx .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run download 1 --dir test-logs/run-1 git x_amd64/vet --show-toplevel x_amd64/vet /usr/bin/gh x_amd64/vet rev-�� --show-toplevel gh h )" 5 /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 1 --dir test-logs/run-1 git /usr/bin/git --show-toplevel r /usr/bin/git git rev-�� 48 git ache/node/24.14.0/x64/bin/node --show-toplevel ache/go/1.25.0/xrev-parse 64/bin/node node (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/12345/artifacts
    • Triggering command: /usr/bin/gh gh run download 12345 --dir test-logs/run-12345 FBrfd97FY x_amd64/compile GOINSECURE (http block)
    • Triggering command: /usr/bin/gh gh run download 12345 --dir test-logs/run-12345 Initial commit x_amd64/vet --show-toplevel x_amd64/vet /usr/bin/infocmp.github/workflows/test.md x_amd64/vet rev-�� --show-toplevel infocmp 64/bin/node xterm-color x_amd64/vet /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 12345 --dir test-logs/run-12345 git ache/node/24.14.0/x64/lib/node_modules/npm/node_modules/@npmcli/run-script/lib/node-gyp-bin/node--show-toplevel --show-toplevel r /usr/bin/git git k/gh�� --show-toplevel on rkflow/js/**/*.json /../../.prettiergit erignore 64/bin/node sh (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/12346/artifacts
    • Triggering command: /usr/bin/gh gh run download 12346 --dir test-logs/run-12346 HC8Jsm53M 64/pkg/tool/linux_amd64/vet GOINSECURE go-sdk/internal/rev-parse GOMODCACHE 64/pkg/tool/linux_amd64/vet env xjry-XMFu GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run download 12346 --dir test-logs/run-12346 git x_amd64/vet --show-toplevel x_amd64/vet /usr/bin/infocmpREDACTED.os x_amd64/vet rev-�� --show-toplevel infocmp /usr/bin/git xterm-color x_amd64/vet /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 12346 --dir test-logs/run-12346 git k/_temp/uv-python-dir/node --show-toplevel r /usr/bin/git git k/gh�� 48 on rkflow/js/**/*.json /../../.prettiergit erignore n-dir/node sh (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/2/artifacts
    • Triggering command: /usr/bin/gh gh run download 2 --dir test-logs/run-2 fJrNJ1ZO5 x_amd64/link GOINSECURE on GOMODCACHE x_amd64/link env 6qlpCmiG- .cfg 64/pkg/tool/linux_amd64/vet wc -c < gh-aw.wagit %H %ct %D 9bec86a1f2162088--git-dir ef/N6GE9dzJuLpfUe9tz4e_/ThKvzodBlPIPkS6j74YO (http block)
    • Triggering command: /usr/bin/gh gh run download 2 --dir test-logs/run-2 Update initial file /usr/bin/git GOMODCACHE x_amd64/vet /usr/bin/gh git estl�� --show-toplevel gh ules/.bin/sh download 2 /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 2 --dir test-logs/run-2 git /usr/bin/git --show-toplevel r /usr/bin/git git rev-�� ormatted success.github/workflows/test.md git /home/REDACTED/work/gh-aw/gh-aw/actions/setup/js/node_modules/.bin/node --show-toplevel ache/go/1.25.0/xconfig 0/x64/bin/npm node (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/3/artifacts
    • Triggering command: /usr/bin/gh gh run download 3 --dir test-logs/run-3 ipBU_UDMP 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD erignore 64/pkg/tool/linux_amd64/vet env ortcfg .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE 9bec86a1f2162088rev-parse GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run download 3 --dir test-logs/run-3 --auto x_amd64/vet --detach e9tz4e_/ThKvzodBconfig /usr/bin/gh x_amd64/vet rev-�� --show-toplevel gh bin/sh download 3 /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 3 --dir test-logs/run-3 --jq ache/go/1.25.0/x64/bin/go --show-toplevel r /usr/bin/git git rev-�� 48 git 0/x64/bin/node --show-toplevel 64/pkg/tool/linurev-parse n-dir/node 0/x64/bin/node (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/4/artifacts
    • Triggering command: /usr/bin/gh gh run download 4 --dir test-logs/run-4 Y1Y9_oHNk 64/pkg/tool/linux_amd64/vet GOINSECURE age erignore 64/pkg/tool/linux_amd64/vet env _jk-OnU_6 .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run download 4 --dir test-logs/run-4 git /usr/bin/git --show-toplevel x_amd64/vet /usr/bin/gh git rev-�� --show-toplevel gh /usr/bin/git download 4 /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 4 --dir test-logs/run-4 git ache/go/1.25.0/x64/pkg/tool/linux_amd64/compile --show-toplevel r /usr/bin/git ache/go/1.25.0/x64/pkg/tool/linux_amd64/compile rev-�� /ref/tags/v8 git /home/REDACTED/work/gh-aw/gh-aw/node_modules/.bin/node --show-toplevel ache/go/1.25.0/xrev-parse x86_64/node node (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/5/artifacts
    • Triggering command: /usr/bin/gh gh run download 5 --dir test-logs/run-5 GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD erignore 64/pkg/tool/linux_amd64/vet ortc�� YFesNwKSb .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE %H %ct %D GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run download 5 --dir test-logs/run-5 git x_amd64/vet --show-toplevel x_amd64/vet /opt/hostedtoolc--show-toplevel x_amd64/vet rev-�� --show-toplevel /opt/hostedtoolcache/node/24.14.0/x64/bin/node /usr/bin/git GOMODCACHE x_amd64/vet /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run download 5 --dir test-logs/run-5 git ache/go/1.25.0/x64/pkg/tool/linu--limit --show-toplevel r /usr/bin/git ache/go/1.25.0/x64/pkg/tool/linux_amd64/asm rev-�� --show-toplevel git /home/REDACTED/work/gh-aw/node_modules/.bin/node --show-toplevel 64/pkg/tool/linurev-parse /usr/bin/git node (http block)
  • https://api.github.com/repos/github/gh-aw/actions/workflows
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path th .prettierignogo1.25.0 GO111MODULE x_amd64/compile GOINSECURE b5M9MKo/46JKhud_-unsafeptr=false GOMODCACHE x_amd64/compile env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD igFiles,SwigCXXF-bool x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh run list --json databaseId,number,url,status,conclusion,workflowName,createdAt,startedAt,updatedAt,event,headBranch,headSha,displayTitle --workflow nonexistent-workflow-12345 --limit 100 GOMOD GOMODCACHE x_amd64/compile 0/x6�� -json GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run list --json databaseId,number,url,status,conclusion,workflowName,createdAt,startedAt,updatedAt,event,headBranch,headSha,displayTitle --workflow nonexistent-workflow-12345 --limit 6 GOMOD GOMODCACHE 64/pkg/tool/linurev-parse ortc�� e=false .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE %H %ct %D GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/v1.0.0
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.0.0 --jq .object.sha y-test.md GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet ortc�� psFdWuxmu g/stringutil/ansi.go 64/pkg/tool/linux_amd64/vet GOINSECURE b/gh-aw/pkg/tty GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.0.0 --jq .object.sha /ref/tags/v8 on ache/node/24.14.0/x64/bin/node /../../.prettiergit erignore /usr/bin/git sh t-33�� sistency_GoAndJavaScript21620190remote.origin.url git /home/node_modules/.bin/node --show-toplevel /opt/hostedtoolcremote /usr/bin/git node (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/v1.2.3
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.2.3 --jq .object.sha -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env */*.ts' '**/*.js-s GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.2.3 --jq .object.sha h ../../../.prettierignore git /usr/bin/git --get remote.origin.ur-atomic /usr/bin/git git rev-�� --show-toplevel git /usr/bin/git --get remote.origin.urrev-parse e/git git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.2.3 --jq .object.sha 1413794521/.github/workflows git tions/node_modules/.bin/sh --show-toplevel 64/pkg/tool/linu-w /usr/bin/git git rev-�� *.json' '!../../OUTPUT git /usr/bin/git --show-toplevel 64/pkg/tool/linu-C /usr/bin/git git (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/v2.0.0
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v2.0.0 --jq .object.sha -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env */*.ts' '**/*.js-s GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v2.0.0 --jq .object.sha -json x86.go x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env */*.ts' '**/*.js-p GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v2.0.0 --jq .object.sha -json eyset.go x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env */*.ts' '**/*.js-test.timeout=10m0s GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/v3.0.0
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v3.0.0 --jq .object.sha -json 8601/parse.go x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env */*.ts' '**/*.js-errorsas GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v3.0.0 --jq .object.sha --show-toplevel git /sh --get remote.origin.ur-o /usr/bin/git e/git rev-�� js/**/*.json' ---s git /opt/hostedtoolc-buildmode=exe /tmp/go-build384git -pack ache/go/1.25.0/x/tmp/TestGuardPolicyBlockedUsersExpressionCompiledOutput4228800606/001 node (http block)
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v3.0.0 --jq .object.sha 0704/001/stability-test.md git h --show-toplevel 64/pkg/tool/linu-w /usr/bin/git git rev-�� *.json' '!../../-nxv git ser.test --show-toplevel 64/pkg/tool/linu-C (http block)
  • https://api.github.com/repos/nonexistent/action/git/ref/tags/v999.999.999
    • Triggering command: /usr/bin/gh gh api /repos/nonexistent/action/git/ref/tags/v999.999.999 --jq .object.sha ortcfg .cfg At,event,headBranch,headSha,displayTitle GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet env ithout_min-integrity3671886613/001 .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE l GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh api /repos/nonexistent/action/git/ref/tags/v999.999.999 --jq .object.sha --show-toplevel on rkflow/js/**/*.json /../../.prettiergit erignore 64/bin/node sh -c 2754992355/.github/workflows git /opt/hostedtoolcache/node/24.14.0/x64/lib/node_modules/npm/node_modules/@npmcli/run-script/lib/n/tmp/TestHashConsistency_GoAndJavaScript3699074546/001/test-frontmatter-with-nested-objects.md l ache/go/1.25.0/xconfig /usr/bin/git node (http block)
  • https://api.github.com/repos/nonexistent/repo/actions/runs/12345
    • Triggering command: /usr/bin/gh gh run view 12345 --repo nonexistent/repo --json status,conclusion GOINSECURE GOMOD erignore 64/pkg/tool/linux_amd64/vet env 2895405479/.github/workflows .cfg 64/pkg/tool/linux_amd64/vet GOINSECURE 9907727/b012/ GOMODCACHE 64/pkg/tool/linux_amd64/vet (http block)
    • Triggering command: /usr/bin/gh gh run view 12345 --repo nonexistent/repo --json status,conclusion --show-toplevel x_amd64/vet /usr/bin/gh git rev-�� --show-toplevel gh ndor/bin/sh view 12345 /usr/bin/git git (http block)
    • Triggering command: /usr/bin/gh gh run view 12345 --repo nonexistent/repo --json status,conclusion --show-toplevel ache/go/1.25.0/xrev-parse ode-gyp-bin/sh git rev-�� --show-toplevel git /home/REDACTED/work/gh-aw/gh-aw/actions/setup/js/node_modules/.bin/sh ./../.prettieriggit ache/go/1.25.0/xrev-parse /usr/bin/git sh (http block)
  • https://api.github.com/repos/owner/repo/actions/workflows
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path --repo owner/repo x_amd64/asm GOINSECURE GOMOD GOMODCACHE x_amd64/asm env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path --repo owner/repo x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile env -json /color.go x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path --repo owner/repo /usr/bin/git v1.0.0 -buildtags /usr/bin/git git rev-�� ath ../../../.pr**/*.json git /usr/bin/git --show-toplevel -tests /usr/bin/git git (http block)
  • https://api.github.com/repos/owner/repo/contents/file.md
    • Triggering command: /tmp/go-build3847149369/b400/cli.test /tmp/go-build3847149369/b400/cli.test -test.testlogfile=/tmp/go-build3847149369/b400/testlog.txt -test.paniconexit0 -test.v=true -test.parallel=4 -test.timeout=10m0s -test.run=^Test -test.short=true GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /tmp/go-build2624206296/b400/cli.test /tmp/go-build2624206296/b400/cli.test -test.testlogfile=/tmp/go-build2624206296/b400/testlog.txt -test.paniconexit0 -test.v=true -test.parallel=4 -test.timeout=10m0s -test.run=^Test -test.short=true sistency_GoAndJash -buildtags kflow.test git ache�� --show-toplevel nly /usr/bin/git /tmp/go-build384sh -importcfg /usr/bin/infocmpnpx prettier --write '../../../**/*.json' '!../../../pkg/workflow/js/**/*.json' --ignore-path git (http block)
    • Triggering command: /tmp/go-build3717779327/b001/cli.test /tmp/go-build3717779327/b001/cli.test -test.testlogfile=/tmp/go-build3717779327/b001/testlog.txt -test.paniconexit0 -test.v=true -test.parallel=4 -test.timeout=10m0s -test.run=^Test -test.short=true REDACTED.os x_amd64/vet /usr/bin/git git rev-�� '**/*.ts' '**/*.json' --ignore-path ../../../.pr**/*.json git /usr/bin/git --show-toplevel 64/pkg/tool/linurev-parse /usr/bin/git git (http block)
  • https://api.github.com/repos/test-owner/test-repo/actions/secrets
    • Triggering command: /usr/bin/gh gh api /repos/test-owner/test-repo/actions/secrets --jq .secrets[].name -json GO111MODULE x_amd64/asm GOINSECURE GOMOD GOMODCACHE x_amd64/asm env -json GO111MODULE x_amd64/compile GOINSECURE GOMOD GOMODCACHE x_amd64/compile (http block)
    • Triggering command: /usr/bin/gh gh api /repos/test-owner/test-repo/actions/secrets --jq .secrets[].name ignore-path ../../../.prettierignore 7149369/b441/testutil.test /usr/bin/git t0 -buildtags (http block)
    • Triggering command: /usr/bin/gh gh api /repos/test-owner/test-repo/actions/secrets --jq .secrets[].name --show-toplevel /usr/bin/git 0/x64/bin/node -v x_amd64/vet /usr/bin/git git 0/x6�� 00/001/test-frontmatter-with-arrays.md git tions/setup/node_modules/.bin/sh --show-toplevel 64/pkg/tool/linu-1 /usr/bin/git git (http block)

If you need me to access, download, or install something from one of these locations, you can either:


📍 Connect Copilot coding agent with Jira, Azure Boards or Linear to delegate work to Copilot in one click without leaving your project management tool.

Copilot AI changed the title [WIP] Update github.com/securego/gosec/v2 from v2.24.7 to v2.25.0 chore: update github.com/securego/gosec/v2 from v2.24.7 to v2.25.0 Mar 23, 2026
Copilot AI requested a review from pelikhan March 23, 2026 17:08
@pelikhan pelikhan marked this pull request as ready for review March 23, 2026 17:10
Copilot AI review requested due to automatic review settings March 23, 2026 17:10
@pelikhan pelikhan merged commit 758bdd9 into main Mar 23, 2026
3 checks passed
@pelikhan pelikhan deleted the copilot/update-gosec-v2-24-7-to-v2-25-0 branch March 23, 2026 17:10
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Go module dependencies to bump github.com/securego/gosec/v2 (and related transitive modules) to newer versions.

Changes:

  • Bump github.com/securego/gosec/v2 from v2.24.7 to v2.25.0
  • Update transitive dependencies including github.com/openai/openai-go/v3, golang.org/x/net, golang.org/x/tools, and google.golang.org/genai
  • Refresh go.sum checksums to match the new module versions

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
go.mod Updates required module versions (gosec and transitive indirect deps).
go.sum Updates dependency checksums to reflect the new module versions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

github.com/rhysd/actionlint v1.7.11
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
github.com/securego/gosec/v2 v2.24.7
github.com/securego/gosec/v2 v2.25.0
Copy link

Copilot AI Mar 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

go.mod bumps github.com/securego/gosec/v2 to v2.25.0, but the repo still installs older gosec versions in CI/automation (e.g. .github/workflows/security-scan.yml installs @v2.22.11, and Makefile installs @v2.23.0). This can lead to developers/CI running different rule sets than the version tracked in go.mod. Consider updating those install pins to v2.25.0, or deriving the installed version from go.mod to keep them in sync.

Suggested change
github.com/securego/gosec/v2 v2.25.0
github.com/securego/gosec/v2 v2.23.0

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deps] Update github.com/securego/gosec/v2 from v2.24.7 to v2.25.0

3 participants