惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Know Your Adversary
Know Your Adversary
博客园 - 叶小钗
量子位
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
博客园 - Franky
有赞技术团队
有赞技术团队
博客园 - 聂微东
腾讯CDC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
Last Week in AI
Last Week in AI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cloudbric
Cloudbric
WordPress大学
WordPress大学
W
WeLiveSecurity
V2EX - 技术
V2EX - 技术
博客园_首页
S
Security @ Cisco Blogs
The Last Watchdog
The Last Watchdog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Security Latest
Security Latest
L
Lohrmann on Cybersecurity
T
Threat Research - Cisco Blogs
Forbes - Security
Forbes - Security
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
The Hacker News
The Hacker News
B
Blog RSS Feed
C
CXSECURITY Database RSS Feed - CXSecurity.com
Schneier on Security
Schneier on Security
T
Troy Hunt's Blog
The GitHub Blog
The GitHub Blog
Hacker News: Ask HN
Hacker News: Ask HN
Spread Privacy
Spread Privacy
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
GbyAI
GbyAI
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
罗磊的独立博客
Blog — PlanetScale
Blog — PlanetScale
M
MIT News - Artificial intelligence
T
Tor Project blog
S
Security Affairs
Security Archives - TechRepublic
Security Archives - TechRepublic
NISL@THU
NISL@THU
P
Proofpoint News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Secure Your Go Apps Before Production Does It For You
Shrijith Ven · 2026-05-12 · via DEV Community

Hello, I'm Shrijith Venkatramana. I'm building git-lrc, an AI code reviewer that runs on every commit. Star Us to help devs discover the project. Do give it a try and share your feedback for improving the product.


Go has a reputation for simplicity and reliability.

But secure by default? Not really.

A lot of Go services today are glued together from:

  • third-party modules
  • cloud SDKs
  • Docker images
  • internal tooling
  • Kubernetes manifests
  • CI pipelines
  • copied snippets from old repos

And that means your attack surface is no longer just your Go code.

The good news is that the Go ecosystem has quietly built an excellent set of security tools over the past few years. Some focus on your source code. Some scan dependencies. Some hunt leaked credentials. Others scan entire containers and infrastructure configs.

A few are genuinely excellent.

This guide breaks down the Go security scanners actually worth knowing in 2026 — what they’re good at, where they fall short, and how teams are using them in practice.


1. Gosec — Still the Default Go Security Scanner

If you ask most Go engineers what security scanner they use, the answer is probably going to be Gosec.

Gosec

It performs static analysis on Go code and looks for common security mistakes:

  • weak cryptography
  • SQL injection patterns
  • unsafe file permissions
  • command execution issues
  • risky imports
  • integer overflows
  • hardcoded credentials

The big reason people still use it is simple:

It understands Go idioms reasonably well.

A generic scanner often struggles with Go’s patterns around interfaces, error handling, context propagation, or concurrency. Gosec was built specifically for this ecosystem.

A minimal setup looks like:

gosec ./...

Enter fullscreen mode Exit fullscreen mode

And that already catches surprising things in mature codebases.

Where it works well

  • CI pipelines
  • Internal backend services
  • Monorepos with many small Go services
  • Teams wanting quick wins fast

Where it gets annoying

False positives.

You will eventually end up with:

// #nosec

Enter fullscreen mode Exit fullscreen mode

sprinkled in places where the scanner is technically correct but practically irrelevant.

That’s not unique to Gosec though. Almost every SAST tool eventually becomes a signal-to-noise battle.


2. Govulncheck — The Official Go Team Scanner

This one changed the conversation around dependency scanning.

Govulncheck

Most dependency scanners work like this:

“You imported package X. Package X once had a CVE. Panic.”

govulncheck does something smarter.

It performs reachability analysis.

Meaning:

  • not just “is the vulnerable package present?”
  • but “does your code actually call the vulnerable path?”

That dramatically cuts down noise.

Example:

  • your dependency tree may contain a vulnerable parser
  • but if your code never invokes the vulnerable function
  • govulncheck stays quiet

That sounds small until you compare outputs side-by-side with older SCA tools that generate hundreds of irrelevant alerts.

Why Go engineers like it

Because it behaves like an engineering tool rather than a compliance tool.

Install:

go install golang.org/x/vuln/cmd/govulncheck@latest

Enter fullscreen mode Exit fullscreen mode

Run:

govulncheck ./...

Enter fullscreen mode Exit fullscreen mode

That’s it.

Limitation

It focuses on Go modules.

It will not help you with:

  • vulnerable Docker base images
  • Terraform
  • Helm charts
  • leaked secrets
  • business logic flaws

So think of it as one layer, not the whole security strategy.


3. Semgrep — The “Fast Enough For CI” Scanner

Semgrep

Semgrep became popular because developers actually tolerated using it.

That sounds trivial, but it matters.

A lot of traditional enterprise scanners are:

  • painfully slow
  • opaque
  • difficult to customize
  • impossible to reason about

Semgrep took the opposite route.

Rules are YAML-based and readable enough that normal engineers can author them.

Example:

pattern: exec.Command(...)

Enter fullscreen mode Exit fullscreen mode

That simplicity is a huge reason security teams adopted it.


What Semgrep is especially good at

Custom organizational rules.

For example:

  • banning dangerous internal APIs
  • enforcing auth middleware
  • preventing raw SQL usage
  • checking tenancy validation
  • detecting unsafe deserialization

This is where Semgrep becomes much more powerful than “generic vulnerability scanning.”

Caveat

The free Community Edition has limitations around cross-file and interprocedural analysis.

Meaning:

  • it can miss vulnerabilities spanning multiple files
  • deep taint tracking is limited unless you use paid tiers

Still, for speed-to-value, Semgrep is hard to beat.


4. Staticcheck — Not Marketed As Security, But Extremely Useful

Staticcheck

Staticcheck is technically more of a correctness and quality tool.

But security bugs often begin as correctness bugs.

Things like:

  • broken error handling
  • nil pointer assumptions
  • ignored return values
  • unreachable branches
  • race-prone logic

These eventually become production vulnerabilities.

What engineers love about Staticcheck is its precision.

Unlike many linters:

  • warnings are usually actionable
  • output is low-noise
  • results rarely feel random

That matters a lot in large teams.

A scanner developers ignore is effectively useless.


5. OSV-Scanner — Dependency Scanning Without The Bloat

OSV-Scanner

Google’s OSV ecosystem has quietly become one of the better vulnerability databases around.

OSV-Scanner integrates directly with it.

One interesting detail:
it often uses precise commit-level matching instead of broad version-range guessing.

That reduces ambiguity significantly.

This matters because traditional CVE tooling sometimes produces alerts like:

“Somewhere between versions 1.2 and 9.7 something may be vulnerable.”

Which is not particularly operationally useful.

Good use cases

  • validating go.mod
  • CI dependency checks
  • supply chain visibility
  • SBOM workflows

Not good at

Anything involving:

  • your actual application logic
  • auth flaws
  • injection issues
  • insecure business workflows

It only knows known vulnerabilities.


6. Trivy — The Security Tool Everyone Eventually Installs

Trivy

At some point most containerized teams end up adopting Trivy.

Because it scans almost everything:

  • containers
  • filesystem dependencies
  • Kubernetes manifests
  • Terraform
  • secrets
  • SBOMs

And surprisingly, it does this without feeling horribly bloated.

A common pattern today looks like:

trivy image myapp:latest

Enter fullscreen mode Exit fullscreen mode

before deployment.

Why it became popular

Because modern production risk often sits outside the Go binary itself.

Example:

  • vulnerable Alpine image
  • outdated OpenSSL package
  • risky Kubernetes config
  • exposed IAM permissions

Your Go code can be perfectly secure while your deployment stack is not.

Trivy helps bridge that gap.

Limitation

It is broad rather than deeply specialized.

So:

  • excellent infrastructure coverage
  • less sophisticated Go AST analysis compared to dedicated SAST tools

7. Gitleaks — Fast Secret Detection That Developers Won’t Hate

Gitleaks

Hardcoded secrets remain one of the most common ways companies leak credentials.

And yes:
even experienced engineers do this accidentally.

Especially during:

  • debugging
  • temporary testing
  • rushed production fixes
  • local cloud experiments

Gitleaks is popular because it is fast enough to run before commits.

That changes behavior.

If secret scanning only happens later in CI, developers psychologically treat it as “someone else’s problem.”

Pre-commit hooks create immediate feedback.

Example:

gitleaks detect

Enter fullscreen mode Exit fullscreen mode

Important limitation

Regex-based detection has tradeoffs.

It can tell you:

“This looks like an AWS key.”

But not:

  • whether it’s active
  • expired
  • fake
  • already revoked

Still incredibly useful.


8. TruffleHog — Secret Scanning With Verification

TruffleHog

TruffleHog takes secret scanning further.

If it detects credentials, it may attempt verification against the provider.

Meaning:

  • AWS keys
  • GitHub tokens
  • Slack tokens
  • cloud credentials

can sometimes be validated automatically.

This dramatically reduces alert fatigue.

Because the worst kind of security tooling is:

  • 500 alerts
  • 497 meaningless
  • engineers stop caring

Tradeoff

Verification takes time.

So TruffleHog is slower than Gitleaks.

In practice:

  • Gitleaks fits better for pre-commit
  • TruffleHog fits better for CI or org-wide audits

A lot of teams actually run both.


9. Snyk — Extremely Good UX, Expensive At Scale

Snyk

Snyk became successful partly because it understood something many security vendors ignored:

Developers care about workflow friction.

The IDE integrations are genuinely good.
The onboarding is smooth.
The remediation guidance is usually understandable.

Compared to older enterprise security tooling, the experience feels much more developer-centric.

Why teams adopt it

Unified visibility:

  • SCA
  • SAST
  • containers
  • IaC
  • licenses
  • PR integration

all in one place.

Why some teams leave later

Cost.

At scale, pricing can become aggressive:

  • per-seat
  • scan limits
  • enterprise tiers
  • expanding surface area

A small engineering org may love it.
A very large org may eventually replace parts of it with OSS tooling.


10. SonarQube — The Enterprise Giant

SonarQube

SonarQube sits in a slightly different category.

It is less of a focused security scanner and more of an engineering governance platform.

Large organizations use it for:

  • code quality gates
  • compliance
  • technical debt tracking
  • vulnerability management
  • reporting across many repos

This is the sort of tool management dashboards love.

Where it shines

Big enterprises with:

  • hundreds of services
  • compliance requirements
  • audit processes
  • centralized platform engineering

Downsides

It is heavier operationally:

  • server infrastructure
  • maintenance
  • indexing
  • upgrades
  • tuning

And many advanced security capabilities are gated behind paid editions.


What Actually Works In Practice?

A lot of engineers search for:

“the best security scanner”

That’s usually the wrong framing.

Modern security workflows are layered.

A more realistic stack looks like:

Stage Tool
Pre-commit Gitleaks
CI dependency scan Govulncheck
CI static analysis Gosec or Semgrep
Container scan Trivy
Org-wide secret audit TruffleHog

That combination already catches a surprisingly large class of real-world mistakes.


Some Important Reality Checks

Security scanners are useful.

But they are not magic.

They generally struggle with:

  • authorization logic flaws
  • broken multi-tenant isolation
  • business workflow vulnerabilities
  • race conditions involving distributed systems
  • architecture-level trust issues
  • subtle crypto misuse
  • logic bugs involving state machines

And no scanner can reliably answer:

“Does this system behave safely under adversarial conditions?”

That still requires engineering judgment.


Final Thoughts

The Go ecosystem is actually in a pretty healthy place security-wise right now.

You no longer need:

  • giant enterprise platforms
  • painfully slow scanners
  • security teams filing PDFs nobody reads

A small team can assemble a strong open-source security pipeline with relatively little effort.

If I had to recommend a pragmatic stack for most Go teams today:

  • govulncheck for dependency vulnerabilities
  • gosec or Semgrep for code scanning
  • Gitleaks for pre-commit protection
  • Trivy for containers and infrastructure

That gets you very far without introducing massive workflow friction.

And honestly, minimizing friction may be one of the most important security features of all.


git-lrc

*AI agents write code fast. They also silently remove logic, change behavior, and introduce bugs -- without telling you. You often find out in production.

git-lrc fixes this. It hooks into git commit and reviews every diff before it lands. 60-second setup. Completely free.*

Any feedback or contributors are welcome! It's online, source-available, and ready for anyone to use.


AI agents write code fast. They also silently remove logic, change behavior, and introduce bugs -- without telling you. You often find out in production.

git-lrc fixes this. It hooks into git commit and reviews every diff before it lands. 60-second setup. Completely free.

See It In Action

See git-lrc catch serious security issues such as leaked credentials, expensive cloud operations, and sensitive material in log statements

git-lrc-intro-60s.mp4

Why

  • 🤖 AI agents silently break things. Code removed. Logic changed. Edge cases gone. You won't notice until production.
  • 🔍 Catch it before it ships. AI-powered inline comments show you exactly what changed and what looks wrong.
  • 🔁 Build a