Skip to content

fix: restrict file permissions and document CLI path usage (CWE-276,22) - #556

Merged
Harsh4902 merged 2 commits into
microcks:masterfrom
Vaishnav88sk:fix/security-file-permissions
Sep 29, 2026
Merged

Harsh4902 merged 2 commits into
microcks:masterfrom
Vaishnav88sk:fix/security-file-permissions

Conversation

@Vaishnav88sk

Copy link
Copy Markdown
Contributor

Description

This PR addresses several file-related security warnings identified by the gosec SAST scanner.
Security Fixes (CWE-276):

  • G301 / G302: Configuration directories and files were being created with overly permissive access (os.ModePerm / 0644). This has been restricted to 0750 for directories and 0600 for files so that only the owner has access.

False Positive Suppressions (CWE-22):

  • G304 / G703: The scanner flagged potential path traversal risks on os.ReadFile and os.Open. Because this is a local CLI tool, the user intentionally provides these paths (e.g., via CLI flags) or they are sourced from trusted system variables (e.g., GITHUB_OUTPUT). These have been annotated with #nosec to suppress the warnings and document the design choice.

How to test

  1. Run gosec -include=G301,G302,G304,G703 ./... and verify 0 issues are found.
  2. Run the CLI to generate a local config and verify the directory is created with rwxr-x--- (0750) permissions.

Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>
…hs (G304, G703)

Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>

@Harsh4902 Harsh4902 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Harsh4902
Harsh4902 merged commit f4c426f into microcks:master Sep 29, 2026
7 checks passed
@github-actions

Copy link
Copy Markdown

🎉 @Vaishnav88sk

You are now a Microcks community contributor! 💖

Thanks and congrats 🚀 on merging your first pull request! We are delighted and very proud of you! 👏

📢 If you're using Microcks in your organization, please add your company name to this list. 🙏 It really helps the project to gain momentum and credibility. It's a small contribution back to the project with a big impact.

If you need to know why and how to add yourself to the list, please read the blog post "Join the Microcks Adopters list and Empower the vibrant open source Community 🙌"

Kudos and please keep going, we need you 🙌

This branch was successfully deployed

1 active deployment
Build — 361c4ed4 Deployed Sep 29, 2026 by Vaishnav88sk via build-verify-package #747
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants