Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 17, 2025

Bumps securego/gosec from 2.22.2 to 2.22.10.

Release notes

Sourced from securego/gosec's releases.

v2.22.10

Changelog

  • 6be2b51fd78feca86af91f5186b7964d76cb1256 Update go to version 1.25.3 and 1.24.9 in CI (#1404)
  • fddb9427b874cb5177d0b52a31b293deeb83c1b4 chore(deps): update all dependencies (#1402)
  • f6760311e8a3db06e3d2d7e9817874dadcd34a25 Update go to version 1.25.2 and 2.24.8 in CI (#1401)
  • 35f7ec2ca2e35fb91f7684b376a58e0c61f6c2a3 chore(deps): update all dependencies (#1399)
  • 01029f0a74161c70f029d51b61592418038aa4b9 check nil slices, partially check bounds (#1396)
  • 34db3de0ee2c7ee2db87ce232132db29775ca50c Remove unused target from the makefile
  • f5a3b7ab78e0d83f3d73c30c6a029f74bf1825db Use the ginkgo command install by the dependencies
  • 761fcbc36cc182a6abd8b668000120c8b642203f Keep the go module at 1.24 version for compatibility reasons
  • 2238079261fdbec5c6d2eeabdd35506bd2e02707 Remove manual test deps
  • bb08aa3188034402763918bf82511b2c3b70e928 fix: text must be supplied when markdown is used
  • 23597d2569a26d726aa56a59460286afeddcc284 fix: improve error message of CheckAnalyzers
  • 8d7e9d598b887054bde0a84b08680d165bf90068 fix: log panic on SSA
  • 0d8255e75e4957f2469bf048a461484854419eab chore(deps): update all dependencies
  • f9c52aac4b897c84070cb8c8ef0c0d2d2180d532 Update gosec to version v.22.9 in the github action

v2.22.9

Changelog

  • 15d5c61e866bc2e2e8389376a31f1e5e09bde7d8 Update cosign to v2.6.0 and go in the CI to latest version
  • 7b8713e2c9114d7db686be71c260e4e9f7ffc2e9 fix(autofix): unnecessary conversion
  • 64ebfc010618034268272af465bb47dbbb49d64f feat(autofix): update gemini sdk and add anthropic claude
  • 506407e7dfe6979d514d362f0b2d2ea77f49f5c8 feat(G304): add os.Root remediation hint (Autofix) when Go >= 1.24
  • 3ead143f0a3b5ace623f1865ea0f560bf730cd32 chore(deps): update all dependencies
  • e81fba3c3afd54f0740d580297d9206d972d47b9 refactor(G304): remove unused trackJoin helper; no functional change
  • ab078db7b0e0de577588ae298d22d1b490bf136c style: gofmt rules/readfile.go
  • e6218c83ecf834512867fda709dbb096b9cc06aa test(g304): add samples for var perm and var flag with cleaned path\n\n- Ensure G304 does not fire when only non-path args (flag/perm) are variables\n- Both samples use filepath.Clean on the path arg\n- Rules suite remains green (42 passed)
  • 79f835d9c776f61d7d61505970829d8b3610b763 rules(G304): analyze only path arg; ignore flag/perm vars; track Clean and safe Join; fix nil-context panic\n\n- Limit G304 checks to first arg (path) for os.Open/OpenFile/ReadFile, avoiding false positives when flag/perm are variables\n- Track filepath.Clean so cleaned identifiers are treated as safe\n- Consider safe joins: filepath.Join(const|resolvedBase, Clean(var)|cleanedIdent)\n- Record Join(...) assigned to identifiers and allow if later cleaned\n- Fix panic by passing non-nil context in trackJoinAssignStmt\n- All rules tests: 42 passed
  • 40ac53017b81ea0e251e6d04eef0a3434773bf1c rules(G202): detect SQL concat in ValueSpec declarations; add test sample\n\n- Handle var query string = 'SELECT ...' + user style declarations\n- Reuse existing binary expr detection on ValueSpec.Values\n- Add postgres sample mirroring issue #1309 report\n- Rules tests: 42 passed
  • 4be6b11bbcb9a225e44194a8867ee4645a4eb618 chore(deps): update all dependencies
  • 5af1117217e476b56a63eaa9ea28eeeb91fbc5ff chore(deps): update all dependencies
  • 287b46c018ebe8ca18d45aa8fc0ebea927f1e27d chore(deps): update all dependencies
  • cee0aeae8a8b6c2d59571e500bc69010f2630db6 Update gosec version to v2.22.8 in the Github action

v2.22.8

Changelog

  • c9453023c4e81ebdb6dde29e22d9cd5e2285fb16 Add support for go version 1.25.0
  • ef7adab98ce3c9599c340cb6d6e988f666d9a866 Update go version in CI to 1.24.6 and 1.23.12
  • e201bb86c2a1ab06d6773b6185a5c16413267abf chore(deps): update all dependencies
  • ba592afef69e0e9f70adf25b95a15056cd61f015 chore(deps): update all dependencies
  • 2ef6017991fdf27d40052196a32571a0ba71dc9a Update github action to release v2.22.7

v2.22.7

Changelog

  • 32975f4bab0d7b683a88756aaf3fa5502188b476 Fix crash in hardcoded_nonce analyzer
  • 6ea6b35e61f367312f4ec362440c98891830286d Update go action to use release v2.22.6

v2.22.6

Changelog

  • bc3f2145b52adab91f2bee2686c9ad65e65005d6 Update go version to 1.24.5 and 1.23.11 in the CI

... (truncated)

Commits
  • 6be2b51 Update go to version 1.25.3 and 1.24.9 in CI (#1404)
  • fddb942 chore(deps): update all dependencies (#1402)
  • f676031 Update go to version 1.25.2 and 2.24.8 in CI (#1401)
  • 35f7ec2 chore(deps): update all dependencies (#1399)
  • 01029f0 check nil slices, partially check bounds (#1396)
  • 34db3de Remove unused target from the makefile
  • f5a3b7a Use the ginkgo command install by the dependencies
  • 761fcbc Keep the go module at 1.24 version for compatibility reasons
  • 2238079 Remove manual test deps
  • bb08aa3 fix: text must be supplied when markdown is used
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Nov 17, 2025
Bumps [securego/gosec](https://github.com/securego/gosec) from 2.22.2 to 2.22.10.
- [Release notes](https://github.com/securego/gosec/releases)
- [Changelog](https://github.com/securego/gosec/blob/master/.goreleaser.yml)
- [Commits](securego/gosec@136f6c0...6be2b51)

---
updated-dependencies:
- dependency-name: securego/gosec
  dependency-version: 2.22.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/github_actions/securego/gosec-2.22.10 branch from 3a14341 to 99570f4 Compare November 24, 2025 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant