Skip to content

Conversation

@github-actions
Copy link

🚨 Gosec Vulnerability Report for branch private/harsh/soc2-scan

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 481
    • Rule ID: G115
    • Details: integer overflow conversion int -> uint16
    • Confidence: MEDIUM
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 480
    • Rule ID: G115
    • Details: integer overflow conversion int -> uint16
    • Confidence: MEDIUM
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 179
    • Rule ID: G115
    • Details: integer overflow conversion int -> uint16
    • Confidence: MEDIUM
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 178
    • Rule ID: G115
    • Details: integer overflow conversion int -> uint16
    • Confidence: MEDIUM
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/storage/kubernetes/storage.go
    • Line: 748
    • Rule ID: G404
    • Details: Use of weak random number generator (math/rand or math/rand/v2 instead of crypto/rand)
    • Confidence: MEDIUM
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/storage/sql/config.go
    • Line: 318
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/storage/ent/mysql.go
    • Line: 130
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/examples/grpc-client/client.go
    • Line: 33-36
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/examples/example-app/main.go
    • Line: 44
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 479-484
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/cmd/dex/serve.go
    • Line: 177-182
    • Rule ID: G402
    • Details: TLS MinVersion too low.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/pkg/httpclient/httpclient.go
    • Line: 40
    • Rule ID: G402
    • Details: TLS InsecureSkipVerify set true.
    • Confidence: HIGH
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/connector/ldap/ldap.go
    • Line: 265
    • Rule ID: G402
    • Details: TLS InsecureSkipVerify may be true.
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/connector/keystone/keystone.go
    • Line: 41
    • Rule ID: G402
    • Details: TLS InsecureSkipVerify may be true.
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 145
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 144
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 143
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 142
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 141
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 140
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/server/oauth2.go
    • Line: 135
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/connector/saml/saml.go
    • Line: 45
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/connector/linkedin/linkedin.go
    • Line: 21
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/v2/api_grpc.pb.go
    • Line: 38
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/v2/api_grpc.pb.go
    • Line: 29
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/v2/api_grpc.pb.go
    • Line: 28
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/v2/api_grpc.pb.go
    • Line: 27
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/v2/api_grpc.pb.go
    • Line: 26
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/api_grpc.pb.go
    • Line: 32
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/api_grpc.pb.go
    • Line: 28
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/api_grpc.pb.go
    • Line: 27
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/api_grpc.pb.go
    • Line: 26
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

  • File: /home/runner/work/dex/dex/api/api_grpc.pb.go
    • Line: 25
    • Rule ID: G101
    • Details: Potential hardcoded credentials
    • Confidence: LOW
    • Severity: HIGH

@github-actions github-actions bot force-pushed the auto/gosec-scan/private-harsh-soc2-scan branch from a46db93 to 88f72f5 Compare August 28, 2025 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants