From fd87647da156c7a50b23a496bb5f5b0e266ba85e Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Thu, 3 Jul 2025 13:27:51 +0200 Subject: [PATCH] use "#nosec" instead of "nolint:gosec" to be more specific The `#nosec` comment allows ignoring a specific rule; this prevents potentially other "gosec" linting failulres from being silently ignored. Signed-off-by: Sebastiaan van Stijn --- build/replicatedstream_test.go | 7 ++++--- driver/kubernetes/podchooser/podchooser.go | 2 +- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/build/replicatedstream_test.go b/build/replicatedstream_test.go index aefa7f315..33de811e1 100644 --- a/build/replicatedstream_test.go +++ b/build/replicatedstream_test.go @@ -43,7 +43,7 @@ func TestSyncMultiReaderParallel(t *testing.T) { buf := make([]byte, bufferSize) for totalRead < len(data) { // Simulate random read sizes - readSize := mathrand.Intn(bufferSize) //nolint:gosec + readSize := mathrand.Intn(bufferSize) // #nosec G404 -- ignore "Use of weak random number generator (math/rand instead of crypto/rand)" n, err := reader.Read(buf[:readSize]) if n > 0 { @@ -58,14 +58,15 @@ func TestSyncMultiReaderParallel(t *testing.T) { assert.NoError(t, err, "Reader %d error", readerId) - if mathrand.Intn(1000) == 0 { //nolint:gosec + // #nosec G404 -- ignore "Use of weak random number generator (math/rand instead of crypto/rand)" + if mathrand.Intn(1000) == 0 { t.Logf("Reader %d closing", readerId) // Simulate random close return } // Simulate random timing between reads - time.Sleep(time.Millisecond * time.Duration(mathrand.Intn(5))) //nolint:gosec + time.Sleep(time.Millisecond * time.Duration(mathrand.Intn(5))) // #nosec G404 -- ignore "Use of weak random number generator (math/rand instead of crypto/rand)" } assert.Equal(t, len(data), totalRead, "Reader %d total read mismatch", readerId) diff --git a/driver/kubernetes/podchooser/podchooser.go b/driver/kubernetes/podchooser/podchooser.go index 901a31d8d..70145fcfe 100644 --- a/driver/kubernetes/podchooser/podchooser.go +++ b/driver/kubernetes/podchooser/podchooser.go @@ -37,7 +37,7 @@ func (pc *RandomPodChooser) ChoosePod(ctx context.Context) (*corev1.Pod, error) if randSource == nil { randSource = rand.NewSource(time.Now().Unix()) } - rnd := rand.New(randSource) //nolint:gosec // no strong seeding required + rnd := rand.New(randSource) // #nosec G404 -- no strong seeding required n := rnd.Int() % len(pods) logrus.Debugf("RandomPodChooser.ChoosePod(): len(pods)=%d, n=%d", len(pods), n) return pods[n], nil