Build the clusters query with Sprintf, as the other handlers do
CI / chart (push) Successful in 1s
CI / security (push) Successful in 20s
CI / test (push) Successful in 5m15s
Release / test (push) Successful in 7s
Release / chart (push) Successful in 4s
Release / binaries (push) Successful in 24s
Release / image (push) Successful in 1m12s
Release / scan-image (push) Successful in 24s

gosec's G202 flagged the string concatenation in handleListClusters, and the
security job gates CI. The pieces joined were only placeholders and fixed
clauses, never request data, so this was not an injection; but every other
handler here builds its SQL with fmt.Sprintf over placeholders, and this one
now reads the same way. The query and its result are unchanged.
This commit is contained in:
Niklas Ye
2026-10-08 18:28:26 +02:00
parent 2bc8f336a0
commit c4833067f0
+2 -2
View File
@@ -33,8 +33,8 @@ func handleListClusters(db *sql.DB) http.HandlerFunc {
label := args.add(originLabel)
rows, err := db.QueryContext(r.Context(),
"SELECT DISTINCT group_labels->>"+label+" AS v FROM incidents WHERE "+
strings.Join(where, " AND ")+" AND group_labels->>"+label+" <> '' ORDER BY v LIMIT 200",
fmt.Sprintf("SELECT DISTINCT group_labels->>%[1]s AS v FROM incidents WHERE %[2]s AND group_labels->>%[1]s <> '' ORDER BY v LIMIT 200",
label, strings.Join(where, " AND ")),
args.all()...)
if err != nil {
respond(w, http.StatusInternalServerError, errResp("internal error"))