Summary
Togoder Security scanned the Go package github.com/fsnotify/fsnotify@v1.9.0 on Oct 5, 2026. An AI review of 30 source files produced 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
Resource limit adjustment
NPS-8CD06EF8E7BB
The SetRlimit function raises the process's open file descriptor limit to the system maximum. This is a legitimate system tuning operation common in file-watcher or server applications, not a malicious pattern.
System information query
NPS-9BE7D8224F77
SysctlUint32 calls retrieve kernel.maxfiles and kern.maxfilesperproc system values to cap maxfiles. This is read-only system introspection with no external communication.
Resource limit modification
NPS-2B8784A80C6E
SetRlimit() raises the soft limit of RLIMIT_NOFILE to the hard limit. This is a normal system configuration operation, not a security concern.
Potential regular expression denial of service (ReDoS)
NPS-A026C032E5DD
DiffMatch compiles user-supplied patterns into Go regexps and can match them against arbitrary 'have' input. Although Go's regexp engine is RE2-based and linear-time, complex patterns constructed from the %(..) substitutions (especially %(ANY) mapped to .+?) combined with large inputs can still cause excessive CPU usage. This is test-only code, but callers should be aware that untrusted 'want' patterns are embedded into regexes.
Regex injection via crafted 'want' pattern
NPS-C97764D4C924
The %(..) replacement in DiffMatch takes the inner text of the pattern and, after QuoteMeta, returns it mostly unescaped (strings.ReplaceAll(m[3:len(m)-2], \, ``)). This allows arbitrary regex constructs (except backslash) to be injected, including .*, character classes, anchors, etc. In a test-helper context this is intended behavior, but if 'want' originates from untrusted input it amounts to regex injection. No code execution or data exfiltration occurs.
Error message leaks raw input
NPS-0375A2485FEE
In applyOpt, when JSON formatting fails the raw 'have'/'want' content is embedded into an error string returned to the caller. This could expose sensitive data present in test fixtures/inputs in logs or CI output. It is a test utility, so exposure is limited, but it is still a minor information-disclosure concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/ztest/diff.go | medium | No malicious patterns (no network, exec, credential harvesting, or persistence) were found; only minor test-time concerns around regex handling and error message content. |
| backend_fen.go | safe | Cleared by Jev triage; no further analysis needed |
| backend_inotify.go | safe | This is the legitimate fsnotify Linux inotify implementation; no malicious patterns, exfiltration, or dynamic code execution were found. |
| backend_kqueue.go | safe | No malicious patterns detected; the code is a legitimate BSD/macOS kqueue-based file system notification backend from the fsnotify library. |
| backend_other.go | safe | Cleared by Jev triage; no further analysis needed |
| backend_windows.go | safe | This is the legitimate Windows backend implementation of the fsnotify library using ReadDirectoryChangesW; no malicious patterns, exfiltration, or backdoors were detected. |
| cmd/fsnotify/closewrite.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/fsnotify/dedup.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/fsnotify/file.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/fsnotify/main.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/fsnotify/watch.go | safe | Cleared by Jev triage; no further analysis needed |
| fsnotify.go | safe | No malicious patterns detected in fsnotify.go; the code is a legitimate cross-platform file system notification library with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| internal/darwin.go | safe | The code performs legitimate Darwin-specific resource limit tuning and FIFO/device-node creation helpers with no malicious behavior. |
| internal/debug_darwin.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_dragonfly.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_freebsd.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_kqueue.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_linux.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_netbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_openbsd.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_solaris.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/debug_windows.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/freebsd.go | safe | No malicious patterns detected |
| internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/unix.go | safe | No malicious patterns detected; code only adjusts file descriptor limits and provides filesystem utility wrappers. |
Show 5 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/unix2.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/windows.go | safe | No malicious patterns detected; the file contains only Windows-specific stubs and a privilege check using standard library APIs. |
| shared.go | safe | Cleared by Jev triage; no further analysis needed |
| system_bsd.go | safe | Cleared by Jev triage; no further analysis needed |
| system_darwin.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/fsnotify/fsnotify safe to use?
No confirmed malware was found in github.com/fsnotify/fsnotify@v1.9.0, but the review flagged 6 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/fsnotify/fsnotify contain malware?
No malware was identified in github.com/fsnotify/fsnotify@v1.9.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/fsnotify/fsnotify checked?
Togoder Security downloaded the published Go package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/fsnotify/fsnotify together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/fsnotify/fsnotify@v1.9.0, cost nothing.