Togoder security

Go package security report

github.com/fsnotify/fsnotify@v1.9.0 security report

Risky patterns found that deserve a look.

Needs review Version v1.9.0 Files reviewed 30 Size 116.2 KB Scanned

Summary

Togoder Security scanned the Go package github.com/fsnotify/fsnotify@v1.9.0 on Oct 5, 2026. An AI review of 30 source files produced 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
6
low

Findings 6

low

Resource limit adjustment

NPS-8CD06EF8E7BB

The SetRlimit function raises the process's open file descriptor limit to the system maximum. This is a legitimate system tuning operation common in file-watcher or server applications, not a malicious pattern.

internal/darwin.go:18
low

System information query

NPS-9BE7D8224F77

SysctlUint32 calls retrieve kernel.maxfiles and kern.maxfilesperproc system values to cap maxfiles. This is read-only system introspection with no external communication.

internal/darwin.go:24
low

Resource limit modification

NPS-2B8784A80C6E

SetRlimit() raises the soft limit of RLIMIT_NOFILE to the hard limit. This is a normal system configuration operation, not a security concern.

internal/unix.go:16
low

Potential regular expression denial of service (ReDoS)

NPS-A026C032E5DD

DiffMatch compiles user-supplied patterns into Go regexps and can match them against arbitrary 'have' input. Although Go's regexp engine is RE2-based and linear-time, complex patterns constructed from the %(..) substitutions (especially %(ANY) mapped to .+?) combined with large inputs can still cause excessive CPU usage. This is test-only code, but callers should be aware that untrusted 'want' patterns are embedded into regexes.

internal/ztest/diff.go
low

Regex injection via crafted 'want' pattern

NPS-C97764D4C924

The %(..) replacement in DiffMatch takes the inner text of the pattern and, after QuoteMeta, returns it mostly unescaped (strings.ReplaceAll(m[3:len(m)-2], \, ``)). This allows arbitrary regex constructs (except backslash) to be injected, including .*, character classes, anchors, etc. In a test-helper context this is intended behavior, but if 'want' originates from untrusted input it amounts to regex injection. No code execution or data exfiltration occurs.

internal/ztest/diff.go
low

Error message leaks raw input

NPS-0375A2485FEE

In applyOpt, when JSON formatting fails the raw 'have'/'want' content is embedded into an error string returned to the caller. This could expose sensitive data present in test fixtures/inputs in logs or CI output. It is a test utility, so exposure is limited, but it is still a minor information-disclosure concern.

internal/ztest/diff.go

Files reviewed

FileVerdictWhat the reviewer saw
internal/ztest/diff.go medium No malicious patterns (no network, exec, credential harvesting, or persistence) were found; only minor test-time concerns around regex handling and error message content.
backend_fen.go safe Cleared by Jev triage; no further analysis needed
backend_inotify.go safe This is the legitimate fsnotify Linux inotify implementation; no malicious patterns, exfiltration, or dynamic code execution were found.
backend_kqueue.go safe No malicious patterns detected; the code is a legitimate BSD/macOS kqueue-based file system notification backend from the fsnotify library.
backend_other.go safe Cleared by Jev triage; no further analysis needed
backend_windows.go safe This is the legitimate Windows backend implementation of the fsnotify library using ReadDirectoryChangesW; no malicious patterns, exfiltration, or backdoors were detected.
cmd/fsnotify/closewrite.go safe Cleared by Jev triage; no further analysis needed
cmd/fsnotify/dedup.go safe Cleared by Jev triage; no further analysis needed
cmd/fsnotify/file.go safe Cleared by Jev triage; no further analysis needed
cmd/fsnotify/main.go safe Cleared by Jev triage; no further analysis needed
cmd/fsnotify/watch.go safe Cleared by Jev triage; no further analysis needed
fsnotify.go safe No malicious patterns detected in fsnotify.go; the code is a legitimate cross-platform file system notification library with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
internal/darwin.go safe The code performs legitimate Darwin-specific resource limit tuning and FIFO/device-node creation helpers with no malicious behavior.
internal/debug_darwin.go safe Cleared by Jev triage; no further analysis needed
internal/debug_dragonfly.go safe Cleared by Jev triage; no further analysis needed
internal/debug_freebsd.go safe Cleared by Jev triage; no further analysis needed
internal/debug_kqueue.go safe Cleared by Jev triage; no further analysis needed
internal/debug_linux.go safe Cleared by Jev triage; no further analysis needed
internal/debug_netbsd.go safe Cleared by Jev triage; no further analysis needed
internal/debug_openbsd.go safe Cleared by Jev triage; no further analysis needed
internal/debug_solaris.go safe Cleared by Jev triage; no further analysis needed
internal/debug_windows.go safe Cleared by Jev triage; no further analysis needed
internal/freebsd.go safe No malicious patterns detected
internal/internal.go safe Cleared by Jev triage; no further analysis needed
internal/unix.go safe No malicious patterns detected; code only adjusts file descriptor limits and provides filesystem utility wrappers.
Show 5 more files
FileVerdictWhat the reviewer saw
internal/unix2.go safe Cleared by Jev triage; no further analysis needed
internal/windows.go safe No malicious patterns detected; the file contains only Windows-specific stubs and a privilege check using standard library APIs.
shared.go safe Cleared by Jev triage; no further analysis needed
system_bsd.go safe Cleared by Jev triage; no further analysis needed
system_darwin.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is github.com/fsnotify/fsnotify safe to use?

No confirmed malware was found in github.com/fsnotify/fsnotify@v1.9.0, but the review flagged 6 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/fsnotify/fsnotify contain malware?

No malware was identified in github.com/fsnotify/fsnotify@v1.9.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/fsnotify/fsnotify checked?

Togoder Security downloaded the published Go package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/fsnotify/fsnotify together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/fsnotify/fsnotify@v1.9.0, cost nothing.

Related security reports