golangci-lint linter gosec showing more errors
than gosec gh. This commit resolve
new errors. And, removing
nosec comments from autogenerated files.
Signed-off-by: subhamkrai <srai@redhat.com>
this commit handle golangci-lint linter errcheck.
`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases
To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`
Signed-off-by: subhamkrai <srai@redhat.com>
this commit handle golangci-lint linter staticcheck error.
`staticcheck` - Staticcheck is a go vet on steroids,
applying a ton of static analysis checks.
To see only `staticcheck` linter output
`golangci-lint run --disable-all -E staticcheck`
Signed-off-by: subhamkrai <srai@redhat.com>
using defer for closing file which are open
for writing is not safe. so closing file again
following below steps:
1. open files
2. defer file.close()
3. write
4.file.close()
these will make sure files are closed.
Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
File permissions need to be reduced to the minimum to avoid config
files from being accessed. While a connection to the pod would be
required to access the files, min privileges are set just as
another layer of security. This fixes gosec error G306.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit fixes where there are areas in which files and directories are
written and created with statically defined permissions. Many of these
permissions are rather open, potentially allowing other system tenants to
view and interact with their contents, which may be sensitive.
Fixed G303: Poor file permissions used for directory by using the most narrow permission
Resoves: https://github.com/rook/rook/issues/4580
Signed-off-by: Nizamudeen <nia@redhat.com>
To ensure a file handle is closed, we defer the close command
so it is guaranteed to run when the method returns. The closing
of the file handle is not going to fail in our usage since we aren't
using the SetDeadline on the files that would cancel a request
and return an error.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit is also part of gosec error handling which handles the following issue:
Fixed G304: Potential File inclusion by cleaning up the file path
Signed-off-by: Nizamudeen <nia@redhat.com>
cmd-reporter runs a command and puts the results of the command into a
ConfigMap defined by its `--config-map-name` commandline flag.
cmd-reporter is intended to be run as a Kubernetes job where an
operator needs to run a single command and get return information back
from the command which is more than just success/failure.
The ConfigMap returned includes `stdout`, `stderr`, and `retcode` data
from the command. The ConfigMap may be preexisting, in which case
cmd-reporter will overwrite the return information in the ConfigMap.
cmd-reporter labels the ConfigMap with `app=cmd-reporter`, and if the
ConfigMap already has an app label which is different, cmd-reporter
fails without modifying the ConfigMap so as not to overwrite another
application's data in the event of a ConfigMap name+namespace collision.
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>