From c4833067f0eba3a6513db9577711de9fa02ee7c8 Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Thu, 8 Oct 2026 18:28:26 +0200 Subject: [PATCH] Build the clusters query with Sprintf, as the other handlers do gosec's G202 flagged the string concatenation in handleListClusters, and the security job gates CI. The pieces joined were only placeholders and fixed clauses, never request data, so this was not an injection; but every other handler here builds its SQL with fmt.Sprintf over placeholders, and this one now reads the same way. The query and its result are unchanged. --- internal/api/incidents.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/internal/api/incidents.go b/internal/api/incidents.go index b98a3ff..19c12a1 100644 --- a/internal/api/incidents.go +++ b/internal/api/incidents.go @@ -33,8 +33,8 @@ func handleListClusters(db *sql.DB) http.HandlerFunc { label := args.add(originLabel) rows, err := db.QueryContext(r.Context(), - "SELECT DISTINCT group_labels->>"+label+" AS v FROM incidents WHERE "+ - strings.Join(where, " AND ")+" AND group_labels->>"+label+" <> '' ORDER BY v LIMIT 200", + fmt.Sprintf("SELECT DISTINCT group_labels->>%[1]s AS v FROM incidents WHERE %[2]s AND group_labels->>%[1]s <> '' ORDER BY v LIMIT 200", + label, strings.Join(where, " AND ")), args.all()...) if err != nil { respond(w, http.StatusInternalServerError, errResp("internal error"))