Skip to content

x/tools/go/analysis/structtag: stricter JSON tag checking #74376

Description

@adonovan

Background: This recent article https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/ describes (among other things) a number of security weaknesses in Go's encoding/json package. Some of these could be mitigated by better static checking of struct field tags; indeed, the author of the post links to two semgrep rules that enforce these checks. Specifically:

  • semgrep -c r/trailofbits.go.unmarshal-tag-is-dash
  • semgrep -c r/trailofbits.go.unmarshal-tag-is-omitempty

Proposal: Let's add these two checks to the structtag analyzer so that users get immediate feedback in their LSP-enabled editor, and whenever they run go vet.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    • Status
      Accepted

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions