fix-gosec-bug-from-issue
Analyze, reproduce, and fix a gosec bug reported in a GitHub issue with a confirmation-gated workflow.
소스 정보
- 저장소
- securego/gosec
- 최근 소스 활동
- 2026년 2월 28일 09:08
- 감지된 SKILL.md 언어
- 영어
- 스타
- 8,959
- 포크
- 717
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
SKILL.md 표시 중
SKILL.md
소스 지침 · 읽기 전용 미리보기- name
- Fix Gosec Bug From Issue
- description
- Analyze, reproduce, and fix a gosec bug reported in a GitHub issue with a confirmation-gated workflow.
# Fix a gosec bug from a GitHub issue
Use this skill when you want to fix a bug described in a GitHub issue.
## Required input
Provide at least:
- GitHub issue URL
Optional but useful:
- gosec version
- Go version (`go version` output)
- OS and environment details
- extra reproduction notes
## Execution workflow
1. Review the GitHub issue thoroughly and extract the problem statement, reproduction hints, expected behavior, and actual behavior.
2. Try to reproduce the issue against the current `master` version of gosec.
3. Analyze the codebase and isolate the root cause.
4. Produce a detailed, minimal fix plan and stop. Ask for confirmation before changing code.
After confirmation, implement end-to-end:
1. Keep the fix small and isolated to the issue scope.
2. Follow good design principles and idiomatic Go.
3. Add tests for both positive and negative cases.
4. When a code sample is appropriate, add or update a sample in `testutils/` in the relevant rule sample file.
5. Validate the result:
- Build succeeds
- Relevant tests pass
- `golangci-lint` has no warnings in changed code
- `gosec` CLI run on a sample confirms the issue is fixed
## Output requirements
- First response must only contain:
- Reproduction status on `master` (or clear blocker)
- Root cause analysis
- Detailed fix plan
- Confirmation request
- Do not implement any code changes until confirmation is provided.
GitHub에서 보기