# github.com/gofrs/uuid@v4.4.0+incompatible security report (Go)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-05T19:10:30.000Z
- Files reviewed: 5
- Findings: 1 low severity finding
- Report: https://security.togoder.click/go/github.com/gofrs/uuid
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/gofrs/uuid@v4.4.0+incompatible on Oct 5, 2026. An AI review of 5 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] CWE-330: Use of Insufficiently Random Values

Finding ID: `NPS-85F9FBD223F6`

File: `generator.go`

V6 and V7 UUIDs use a clock sequence as a monotonic counter. The clock sequence is shared between V1, V6, and V7 and is not reset between generations. This is not a security vulnerability in this context but may be noted for predictability in some use cases. However, no malicious intent is present.

## Files reviewed

- `codec.go` (safe): Cleared by Jev triage; no further analysis needed
- `fuzz.go` (safe): Cleared by Jev triage; no further analysis needed
- `generator.go` (safe): No malicious patterns detected; the code is a legitimate UUID generation library with standard cryptographic practices.
- `sql.go` (safe): Cleared by Jev triage; no further analysis needed
- `uuid.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
