Skip to content

chore(deps): bump github.com/securego/gosec/v2 v2.26.1 → v2.27.0#36220

Merged
pelikhan merged 3 commits into
mainfrom
copilot/update-gosec-v2-26-1-to-2-27-0
Jun 1, 2026
Merged

chore(deps): bump github.com/securego/gosec/v2 v2.26.1 → v2.27.0#36220
pelikhan merged 3 commits into
mainfrom
copilot/update-gosec-v2-26-1-to-2-27-0

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Jun 1, 2026

Minor version bump for gosec bringing fixes for G118 false positives, improved #nosec annotation handling (rule ID and justification requirements), and error position parsing improvements for paths containing colons.

Changes

  • go.mod: Upgraded github.com/securego/gosec/v2 to v2.27.0
  • go.sum: Updated checksums
  • Transitive deps (via go mod tidy): anthropic-sdk-go, openai-go, opentelemetry suite, grpc, cloud.google.com/go, and others pulled forward to satisfy new constraints

Copilot AI and others added 2 commits June 1, 2026 11:33
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update github.com/securego/gosec/v2 to v2.27.0 chore(deps): bump github.com/securego/gosec/v2 v2.26.1 → v2.27.0 Jun 1, 2026
Copilot AI requested a review from pelikhan June 1, 2026 11:36
@pelikhan pelikhan marked this pull request as ready for review June 1, 2026 11:41
Copilot AI review requested due to automatic review settings June 1, 2026 11:41
@pelikhan pelikhan merged commit 93b5189 into main Jun 1, 2026
@pelikhan pelikhan deleted the copilot/update-gosec-v2-26-1-to-2-27-0 branch June 1, 2026 11:42
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR primarily updates the repository’s Go security tooling by bumping github.com/securego/gosec/v2 to v2.27.0, along with the resulting go mod tidy transitive dependency updates. In addition, it updates many workflow “lock” files to always enable the setup action’s safe-output-artifact-client and to run the “daily workflow token guardrail” step unconditionally.

Changes:

  • Bump github.com/securego/gosec/v2 to v2.27.0 and update go.sum accordingly.
  • Pull forward a large set of indirect Go dependencies (Google Cloud, OTel, gRPC, AI SDKs, etc.) due to updated constraints.
  • Update numerous .github/workflows/*.lock.yml files to force safe-output-artifact-client: 'true' and remove conditional execution for the token guardrail step.
Show a summary per file
File Description
go.mod Bumps gosec to v2.27.0 and updates indirect dependency versions.
go.sum Updates module checksums after gosec bump / transitive dependency resolution.
.github/workflows/daily-mcp-concurrency-analysis.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-malicious-code-scan.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-issues-report.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-hippo-learn.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-grafana-otel-instrumentation-advisor.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-geo-optimizer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-function-namer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-firewall-report.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-file-diet.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-fact.lock.yml Forces safe-output artifact client on, removes conditional token guardrail gating, and refreshes embedded heredoc markers.
.github/workflows/daily-experiment-report.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-doc-updater.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-doc-healer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-compiler-quality.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-community-attribution.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-code-metrics.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-cli-tools-tester.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-cli-performance.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-choice-test.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-caveman-optimizer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-cache-strategy-analyzer.lock.yml Forces safe-output artifact client on, removes conditional token guardrail gating, and refreshes embedded heredoc markers.
.github/workflows/daily-byok-ollama-test.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-aw-cross-repo-compile-check.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-assign-issue-to-user.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-architecture-diagram.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-agentrx-trace-optimizer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/craft.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-session-insights.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-pr-prompt-analysis.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-pr-nlp-analysis.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-pr-merged-report.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-opt.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-cli-deep-research.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/copilot-agent-analysis.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/contribution-check.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/constraint-solving-potd.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/commit-changes-analyzer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/codex-github-remote-mcp-test.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/code-simplifier.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/code-scanning-fixer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/cloclo.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/cli-version-checker.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/cli-consistency-checker.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/claude-code-user-docs-review.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/ci-doctor.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/ci-coach.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/chaos-pr-bundle-fuzzer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/changeset.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/breaking-change-checker.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/brave.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/bot-detection.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/blog-auditor.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/aw-failure-investigator.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/avenger.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/auto-triage-issues.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/audit-workflows.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/artifacts-summary.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/architecture-guardian.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/archie.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/approach-validator.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/api-consumption-report.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/ai-moderator.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/agentic-token-optimizer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/agentic-token-audit.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/agent-persona-explorer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/agent-performance-analyzer.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/ace-editor.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.
.github/workflows/ab-testing-advisor.lock.yml Forces safe-output artifact client on and removes conditional token guardrail gating.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 72/73 changed files
  • Comments generated: 2

Comment thread go.mod
github.com/rhysd/actionlint v1.7.12
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
github.com/securego/gosec/v2 v2.26.1
github.com/securego/gosec/v2 v2.27.0
Comment on lines 125 to +127
destination: ${{ runner.temp }}/gh-aw/actions
job-name: ${{ github.job }}
safe-output-artifact-client: ${{ env.GH_AW_MAX_DAILY_EFFECTIVE_TOKENS != '' }}
safe-output-artifact-client: 'true'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deps] Update github.com/securego/gosec/v2 from v2.26.1 to v2.27.0

3 participants