Summary
Togoder Security scanned the Go package github.com/grpc-ecosystem/grpc-gateway/v2@v2.30.0 on Oct 5, 2026. An AI review of 362 source files produced 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
Insecure transport credentials
NPS-A58E4AD0C954
Both dialTCP and dialUnix use insecure.NewCredentials(), meaning all gRPC traffic is transmitted without TLS. This disables server authentication and encryption, allowing man-in-the-middle interception or tampering. While this is an example package, using insecure credentials in a gateway can be a real risk if copied into production code.
Path Traversal
NPS-7EEFC1D036F1
The openAPIServer function takes a path suffix from the URL, trims the '/openapiv2/' prefix, joins it with a base directory, and serves it directly with http.ServeFile. Although path.Join cleans the path, it does not prevent '..' traversal in all cases depending on how it's used, potentially allowing access to files outside the intended directory if the base path is not absolute or if symlinks are involved. The code does not validate that the resolved path stays within the intended directory.
Overly Permissive CORS
NPS-08681360343E
The allowCORS middleware reflects the Origin header back in Access-Control-Allow-Origin, allowing any origin. This defeats the same-origin policy and can expose authenticated endpoints to cross-origin attacks if credentials are used. The comments acknowledge this but it remains a security risk in production.
Insecure transport credentials
NPS-FC81469CB87A
dialUnix also uses insecure.NewCredentials() for unix domain socket connections, omitting TLS on IPC paths that may cross trust boundaries.
Global package-level channel initialization
NPS-4C75302480E1
Package-level variables excessBody_contextChRPC and excessBody_contextChStream are initialized with make(chan context.Context) at package initialization/import time. While not inherently malicious, this is top-level code that runs on import and could be leveraged for goroutine leaks or unintended global state. In this context it appears to be test infrastructure for the grpc-gateway example server.
Blocking channel send without buffering or receiver guarantee
NPS-808E5ECDE88C
Each RPC handler sends ctx or stream.Context() on an unbuffered channel and then blocks on <-ctx.Done(). If no external goroutine calls the RetrieveContext* functions, the handlers will block on the channel send until the context is canceled, potentially causing goroutine leaks or DoS under load. This is a resource-exhaustion concern rather than a data-exfiltration concern; it is consistent with a test harness for verifying context propagation but could be abused if exposed to untrusted clients.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| examples/internal/gateway/gateway.go | medium | The code is a legitimate grpc-gateway example with no malicious patterns, but it uses insecure gRPC transport credentials that disable TLS. |
| examples/internal/gateway/handlers.go | medium | The code contains no malicious patterns but includes a potential path traversal in the OpenAPI file server and an overly permissive CORS configuration, both of which pose security risks in a production environment. |
| examples/internal/server/excess_body.go | medium | This appears to be legitimate grpc-gateway test infrastructure that exposes gRPC contexts via global channels for test verification; the main concerns are unbuffered channel blocking and package-level channel initialization, but no malicious exfiltration, credential harvesting, or command execution patterns are present. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_client.go | safe | This is a standard go-swagger generated API client with no malicious patterns; authentication helpers accept credentials via parameters and do not harvest or exfiltrate any data. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_external_nested_path_enum_parameters.go | safe | No malicious patterns detected; the file is a standard go-swagger generated client parameter struct with no network exfiltration, credential harvesting, obfuscation, process execution, or install-time behavior. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_external_nested_path_enum_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_external_path_enum_parameters.go | safe | No malicious patterns detected in this generated Go Swagger client code; it only defines parameter structs and request-building methods with no network, filesystem, process, or credential access beyond normal HTTP client configuration. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_external_path_enum_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_get_query_params_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter file with only benign getter/setter and query-parameter serialization logic. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_get_query_params_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_nested_enum_get_query_params_parameters.go | safe | Auto-generated go-swagger client parameter binding code with no malicious patterns, network exfiltration, credential harvesting, or dynamic execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_nested_enum_get_query_params_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_post_query_params_parameters.go | safe | This is auto-generated go-swagger client code containing only standard parameter setters and request builders with no malicious patterns, external calls, or obfuscation. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_post_query_params_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_status_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns or suspicious behavior. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_check_status_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_body_parameters.go | safe | No malicious patterns detected; this is standard generated go-swagger client parameter code with no external calls, credential access, or dynamic execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_book_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_book_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_nested_body_oneof_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_nested_body_oneof_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_parameters.go | safe | This is auto-generated go-swagger client parameter code with no network exfiltration, credential harvesting, dynamic execution, or other malicious patterns. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_create_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom2_parameters.go | safe | No malicious patterns detected in this auto-generated go-swagger client parameter file. |
Show 337 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom_options_request_parameters.go | safe | Auto-generated go-swagger client request parameters file with only standard parameter setters and query/path binding logic; no malicious patterns detected. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom_options_request_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_custom_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_deep_path_echo_parameters.go | safe | This is standard go-swagger generated client parameter code with no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_deep_path_echo_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_delete_parameters.go | safe | This is auto-generated go-swagger client parameter code with no malicious patterns; it only constructs request parameters and timeout/context settings. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_delete_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_double_colon_parameters.go | safe | No malicious patterns detected; this is standard go-swagger generated client parameter code for an API request. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_double_colon_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_error_with_details_parameters.go | safe | No malicious patterns detected; this is standard go-swagger generated client parameter code with no network, filesystem, exec, or credential-harvesting behavior. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_error_with_details_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_exists_parameters.go | safe | This is a go-swagger generated client parameter file with no malicious patterns; it only serializes parameters into HTTP requests using the standard go-openapi runtime. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_exists_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_message_with_body_parameters.go | safe | No malicious patterns detected; this is standard generated go-swagger client parameter code with no exfiltration, obfuscation, shell execution, or suspicious behavior. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_message_with_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_query_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated API client parameter file with no external calls, credential harvesting, obfuscation, or suspicious behavior. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_query_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_repeated_query_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter binding file with no network exfiltration, credential harvesting, obfuscation, or process execution code. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_get_repeated_query_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_lookup_parameters.go | safe | Generated go-swagger client parameter code contains no malicious patterns or security concerns |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_lookup_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_overwrite_request_content_type_parameters.go | safe | This auto-generated go-swagger API client parameter file contains only standard request parameter construction and serialization logic with no malicious patterns. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_overwrite_request_content_type_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_overwrite_response_content_type_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_overwrite_response_content_type_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_oneof_enum_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_oneof_enum_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_required_message_type_parameters.go | safe | No malicious patterns detected; this is generated go-swagger client parameter code with standard request construction and no exfiltration, credential harvesting, or dynamic execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_required_message_type_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_with_empty_body_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, network calls, credential access, or dynamic code execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_post_with_empty_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_timeout_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, performing only normal HTTP request parameter configuration. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_timeout_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_book_parameters.go | safe | No malicious patterns detected; the file is generated go-swagger client parameter code with only standard request construction and no exfiltration, credential access, obfuscation, or process execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_book_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_entity_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter file with no unsafe operations. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_entity_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v22_parameters.go | safe | No malicious patterns detected in this auto-generated go-swagger client parameter file. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v22_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v23_parameters.go | safe | No malicious patterns detected; this is standard go-swagger generated client parameter code for an API request with no network, filesystem, process, or dynamic code execution concerns. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v23_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v2_parameters.go | safe | No malicious patterns detected in this generated Go Swagger client parameter file; it only contains standard request parameter handling code. |
| examples/internal/clients/abe/client/a_bit_of_everything/a_bit_of_everything_service_update_v2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/a_bit_of_everything_client.go | safe | No malicious patterns detected in this auto-generated Go HTTP client code. |
| examples/internal/clients/abe/client/camel_case_service_name/camel_case_service_name_client.go | safe | This is a standard go-swagger generated API client with no malicious patterns, no obfuscation, no external data harvesting, and no install-time or runtime side effects beyond normal HTTP client functionality. |
| examples/internal/clients/abe/client/camel_case_service_name/camel_case_service_name_empty_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/camel_case_service_name/camel_case_service_name_empty_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo2_parameters.go | safe | This is auto-generated go-swagger client parameter code with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo3_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo3_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/clients/abe/client/echo_rpc/a_bit_of_everything_service_echo_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/client/echo_rpc/echo_rpc_client.go | safe | No malicious patterns detected; this is standard go-swagger generated client code with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| examples/internal/clients/abe/client/snake_enum_service/snake_enum_service_client.go | safe | No malicious patterns detected; this is standard swagger-generated Go API client code with no exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| examples/internal/clients/abe/client/snake_enum_service/snake_enum_service_snake_enum_parameters.go | safe | No malicious patterns detected; the file is a standard go-swagger generated client parameter struct with only parameter setters and request writing logic. |
| examples/internal/clients/abe/client/snake_enum_service/snake_enum_service_snake_enum_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/a_bit_of_everything_nested.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/a_bit_of_everything_service_deep_path_echo_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/a_bit_of_everything_service_post_with_empty_body_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/a_bit_of_everything_service_update_entity_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/a_bit_of_everything_service_update_v2_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_a_bit_of_everything.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_a_bit_of_everything_repeated.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_a_bit_of_everything_service_update_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_bar.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_body.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_book.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_check_status_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_entity_id.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_error_object.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_error_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_nested_body_oneof.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_numeric_enum.go | safe | The file contains standard go-swagger generated model code with an init() function that only parses a static enum list and no malicious patterns. |
| examples/internal/clients/abe/models/examplepb_required_message_type_request.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/examplepb_snake_case0_enum.go | safe | No malicious patterns detected; the file is generated Go model code for enum validation with no network, filesystem, process execution, or credential access. |
| examples/internal/clients/abe/models/examplepb_snake_case_enum.go | safe | No malicious patterns detected; the file contains standard generated Go enum model code with only local validation and JSON parsing of a hardcoded literal. |
| examples/internal/clients/abe/models/examplepb_snake_enum_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/google_rpc_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/message_path_enum_nested_path_enum.go | safe | No malicious patterns detected; the file is generated Swagger model code with only enum validation logic. |
| examples/internal/clients/abe/models/nested_deep_enum.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/models/oneofenum_example_enum.go | safe | Code is a standard go-swagger generated enum model with only local validation logic and no malicious patterns. |
| examples/internal/clients/abe/models/pathenum_path_enum.go | safe | This is a standard go-swagger generated enum model file with no malicious patterns; the init() function only unmarshals a hardcoded static enum array and panics on error, which is benign generated code. |
| examples/internal/clients/abe/models/pathenum_snake_case_for_import.go | safe | No malicious patterns detected |
| examples/internal/clients/abe/models/proto_examplepb_foo.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/protobuf_any.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/abe/models/sub_string_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_client.go | safe | This is an auto-generated go-swagger API client with standard client constructor, authentication helper functions, and HTTP operation methods; no malicious patterns, exfiltration, credential harvesting, obfuscation, process execution, or dynamic code loading are present. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo2_parameters.go | safe | This is auto-generated go-swagger client parameter code with no malicious patterns, network requests, credential harvesting, or dynamic execution. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo3_parameters.go | safe | This is standard auto-generated go-swagger client parameter code with no malicious patterns, dynamic execution, credential harvesting, or suspicious network activity. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo3_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo4_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, external network calls beyond the intended API client, credential harvesting, code execution, or filesystem manipulation. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo4_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo5_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/echo/client/echo_service/echo_service_echo5_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo6_parameters.go | safe | This is auto-generated go-swagger client parameter code containing only standard parameter setters and request writing logic, with no malicious patterns detected. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo6_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo7_parameters.go | safe | This is a standard go-swagger generated client parameters file with no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo7_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_body2_parameters.go | safe | No malicious patterns detected; the file is a generated go-swagger API client parameter definition with standard request construction behavior. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_body2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_body_parameters.go | safe | This is standard go-swagger generated client code for building request parameters with no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_delete_parameters.go | safe | This is auto-generated go-swagger client parameter code with no malicious patterns, no execution at import time, and no network, filesystem, or process manipulation beyond standard HTTP request parameter setting. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_delete_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_parameters.go | safe | This is auto-generated go-swagger client code for an echo service with standard parameter handling and no malicious patterns detected |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_patch_parameters.go | safe | This is auto-generated go-swagger client parameter code with no network exfiltration, credential harvesting, obfuscation, or process spawning; it only builds an HTTP request from caller-supplied parameters. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_patch_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_status_parameters.go | safe | No malicious patterns detected in the auto-generated Go swagger client parameter file; it performs only standard request parameter handling and context/timeout wiring. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_status_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_unauthorized_parameters.go | safe | No malicious patterns detected; this is standard go-swagger generated client code defining parameter structs and request-writing logic. |
| examples/internal/clients/echo/client/echo_service/echo_service_echo_unauthorized_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/client/echo_service_client.go | safe | Code is a standard go-swagger generated HTTP client for the grpc-gateway echo example with no malicious patterns, no external network calls beyond the configurable API host, no credential harvesting, and no dynamic code execution. |
| examples/internal/clients/echo/models/examplepb_dynamic_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_dynamic_message_update.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_embedded.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_nested_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_simple_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_status_check_request.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/examplepb_status_check_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/google_rpc_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/proto_sub2_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/proto_sub_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/protobuf_any.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/echo/models/protobuf_null_value.go | safe | No malicious patterns detected |
| examples/internal/clients/generateunboundmethods/client/examples_internal_proto_examplepb_generate_unbound_methods_proto_client.go | safe | No malicious patterns detected |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_client.go | safe | No malicious patterns detected; this is a standard generated go-swagger API client with no data exfiltration, credential harvesting, obfuscation, or install-time execution. |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_body_parameters.go | safe | No malicious patterns detected in this auto-generated go-swagger client parameter file. |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_delete_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter file with no network, filesystem, process, or obfuscation concerns. |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_delete_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_parameters.go | safe | This is a go-swagger generated client parameters file with no malicious patterns, external calls, or suspicious activity. |
| examples/internal/clients/generateunboundmethods/client/generate_unbound_methods_echo_service/generate_unbound_methods_echo_service_echo_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/generateunboundmethods/models/examplepb_generate_unbound_methods_simple_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/generateunboundmethods/models/protobuf_any.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/generateunboundmethods/models/rpc_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/helloworldv3/helloworldv3.go | safe | No malicious patterns detected in this auto-generated OpenAPI client code, which only contains standard HTTP request construction and JSON serialization logic with no exfiltration, credential harvesting, or dynamic execution. |
| examples/internal/clients/responsebody/client/examples_internal_proto_examplepb_response_body_service_proto_client.go | safe | No malicious patterns detected; the file is a standard go-swagger generated HTTP client with no execution, data exfiltration, or credential harvesting behavior. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_client.go | safe | No malicious patterns detected; this is a standard go-swagger generated API client with no data exfiltration, credential harvesting, obfuscation, or suspicious execution behavior. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_same_name_parameters.go | safe | No malicious patterns detected in this auto-generated Go client parameter file. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_same_name_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_stream_parameters.go | safe | This is standard go-swagger generated client parameter code with no malicious patterns, network exfiltration, or credential harvesting. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_get_response_body_stream_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_list_response_bodies_parameters.go | safe | No malicious patterns detected in this auto-generated go-swagger client parameter file. |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_list_response_bodies_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_list_response_strings_parameters.go | safe | No malicious patterns detected |
| examples/internal/clients/responsebody/client/response_body_service/response_body_service_list_response_strings_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_repeated_response_body_out.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_repeated_response_body_out_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_repeated_response_strings.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_response_body_out.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_response_body_out_response.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/examplepb_response_body_value.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/google_rpc_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/protobuf_any.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/responsebody/models/response_response_type.go | safe | No malicious patterns detected; this is a standard go-swagger generated enum model file with only validation logic and a safe init() unmarshal. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_client.go | safe | No malicious patterns detected |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_client.go | safe | This is a standard go-swagger generated API client with no malicious patterns, obfuscation, exfiltration, or install-time execution detected. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo2_parameters.go | safe | This is an auto-generated go-swagger client parameter file with no malicious patterns; it only constructs HTTP request parameters using standard libraries. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo2_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_body_parameters.go | safe | This is a standard go-swagger generated client parameter file with no malicious patterns; it only defines request parameter structs and setters. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_body_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_delete_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter file. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_delete_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_nested_parameters.go | safe | No malicious patterns detected; the file is a standard go-swagger generated client parameter struct with no network, filesystem, process, or dynamic execution behavior. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_nested_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_parameters.go | safe | No malicious patterns detected; this is a standard go-swagger generated client parameter file with no external calls, credential harvesting, obfuscation, or shell/process execution. |
| examples/internal/clients/unannotatedecho/client/unannotated_echo_service/unannotated_echo_service_echo_responses.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/models/examplepb_unannotated_embedded.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/models/examplepb_unannotated_nested_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/models/examplepb_unannotated_simple_message.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/models/protobuf_any.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/clients/unannotatedecho/models/rpc_status.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/cmd/example-gateway-server/main.go | safe | No malicious patterns detected; the file is a straightforward example gRPC gateway server with standard flag parsing and no suspicious behavior. |
| examples/internal/cmd/example-grpc-server/main.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/cmd/example-otel-tracing/main.go | safe | No malicious patterns detected; this is a legitimate OpenTelemetry tracing example for grpc-gateway. |
| examples/internal/gateway/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/gateway/main.go | safe | No malicious patterns detected |
| examples/internal/helloworld/helloworld.pb.go | safe | This is a standard protoc-gen-go generated file containing only protobuf message definitions and gRPC service descriptors with no malicious patterns. |
| examples/internal/helloworld/helloworld.pb.gw.go | safe | This is a standard protoc-gen-grpc-gateway generated reverse proxy file with no malicious patterns detected. |
| examples/internal/helloworld/helloworld_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/a_bit_of_everything_grpc.pb.go | safe | No malicious patterns detected; this is standard generated gRPC Go code from protoc-gen-go-grpc containing only service definitions, client/server interfaces, and handlers. |
| examples/internal/proto/examplepb/camel_case_service.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/camel_case_service.pb.gw.go | safe | This is a standard protoc-gen-grpc-gateway generated file that translates gRPC to RESTful JSON APIs with no malicious patterns, obfuscation, network exfiltration, or dynamic code execution. |
| examples/internal/proto/examplepb/camel_case_service_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/echo_service.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for an echo service example with only static descriptor data and no external network, filesystem, or process activity. |
| examples/internal/proto/examplepb/echo_service.pb.gw.go | safe | This is a standard protoc-gen-grpc-gateway generated reverse proxy file with no malicious patterns, as it only contains HTTP-to-gRPC routing boilerplate. |
| examples/internal/proto/examplepb/echo_service_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/enum_with_single_value.pb.go | safe | Generated protobuf Go code contains only standard serialization logic and no malicious patterns. |
| examples/internal/proto/examplepb/enum_with_single_value.pb.gw.go | safe | No malicious patterns detected; this is a standard protoc-gen-grpc-gateway generated reverse proxy file with only gRPC request forwarding and metadata handling. |
| examples/internal/proto/examplepb/enum_with_single_value_grpc.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/excess_body.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/excess_body.pb.gw.go | safe | This is auto-generated grpc-gateway reverse proxy code with no malicious patterns; it only handles normal HTTP request/response translation to gRPC calls. |
| examples/internal/proto/examplepb/excess_body_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/flow_combination.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file containing only protobuf message definitions, descriptors, and gRPC/HTTP binding metadata with no executable, network, filesystem, or credential-harvesting behavior. |
| examples/internal/proto/examplepb/flow_combination_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/generate_unbound_methods.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/generate_unbound_methods.pb.gw.go | safe | This is a standard protoc-gen-grpc-gateway generated file with no malicious patterns, external data exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/proto/examplepb/generate_unbound_methods_grpc.pb.go | safe | This is standard protoc-gen-go-grpc generated code containing only gRPC client/server interface definitions and service registration with no malicious patterns. |
| examples/internal/proto/examplepb/ignore_comment.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code for a proto message definition. |
| examples/internal/proto/examplepb/ignore_comment.pb.gw.go | safe | No malicious patterns detected; generated gRPC-Gateway proxy code with standard request handling and no exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/proto/examplepb/ignore_comment_grpc.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go-grpc generated code implementing a gRPC service interface with no data exfiltration, credential harvesting, command execution, or other suspicious behavior. |
| examples/internal/proto/examplepb/non_standard_names.pb.go | safe | This is a standard protobuf-generated Go file containing only message definitions, accessors, and descriptor metadata with no malicious patterns. |
| examples/internal/proto/examplepb/non_standard_names.pb.gw.go | safe | No malicious patterns detected; this is standard generated grpc-gateway reverse proxy code with no exfiltration, credential harvesting, obfuscation, or command execution. |
| examples/internal/proto/examplepb/non_standard_names_grpc.pb.go | safe | No malicious patterns detected; this is standard gRPC-generated Go code with no data exfiltration, credential harvesting, obfuscation, network calls, or process execution. |
| examples/internal/proto/examplepb/opaque.pb.gw.go | safe | This is auto-generated grpc-gateway reverse proxy code with standard HTTP-to-gRPC translation logic and no malicious patterns. |
| examples/internal/proto/examplepb/opaque_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/openapi.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/openapi_merge_a.pb.go | safe | No malicious patterns detected in this standard protoc-gen-go generated file. |
| examples/internal/proto/examplepb/openapi_merge_a.pb.gw.go | safe | No malicious patterns detected; this is a standard protoc-gen-grpc-gateway generated reverse-proxy handler file with no external data transfers, credential harvesting, obfuscation, or process spawning. |
| examples/internal/proto/examplepb/openapi_merge_a_grpc.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go-grpc generated code for gRPC service definitions with no exfiltration, code execution, or suspicious behavior. |
| examples/internal/proto/examplepb/openapi_merge_b.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code with only benign initialization, reflection, and gzip compression of embedded descriptors. |
| examples/internal/proto/examplepb/openapi_merge_b.pb.gw.go | safe | Code is standard grpc-gateway generated boilerplate with no malicious patterns detected |
| examples/internal/proto/examplepb/openapi_merge_b_grpc.pb.go | safe | This is standard protoc-generated gRPC client/server boilerplate with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| examples/internal/proto/examplepb/proto3_field_semantics.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for protobuf message definitions and descriptors. |
| examples/internal/proto/examplepb/proto3_field_semantics.pb.gw.go | safe | This is a standard auto-generated grpc-gateway reverse proxy file with no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| examples/internal/proto/examplepb/proto3_field_semantics_grpc.pb.go | safe | No malicious patterns detected in this standard protoc-gen-go-grpc generated service file. |
| examples/internal/proto/examplepb/remove_internal_comment.pb.go | safe | This is standard protoc-gen-go generated code with no malicious patterns, network activity, process execution, or credential harvesting. |
| examples/internal/proto/examplepb/remove_internal_comment.pb.gw.go | safe | No malicious patterns detected; this is standard generated grpc-gateway reverse proxy boilerplate with no data exfiltration, credential harvesting, obfuscation, or command execution. |
| examples/internal/proto/examplepb/remove_internal_comment_grpc.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go-grpc generated service code with no executable payloads, network calls, credential access, or filesystem/process manipulation. |
| examples/internal/proto/examplepb/response_body_service.pb.go | safe | Generated Go protobuf code with no malicious patterns; only standard initialization and type registration present. |
| examples/internal/proto/examplepb/response_body_service.pb.gw.go | safe | This is a standard gRPC-Gateway generated file that translates gRPC into RESTful JSON APIs, with no malicious patterns, obfuscation, credential harvesting, or suspicious behavior detected. |
| examples/internal/proto/examplepb/response_body_service_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/stream.pb.go | safe | This is standard generated protobuf Go code from grpc-gateway examples with no malicious patterns, network calls, credential access, or dynamic execution. |
| examples/internal/proto/examplepb/stream.pb.gw.go | safe | This is an auto-generated grpc-gateway reverse proxy file containing only standard RPC routing, decoding, and forwarding logic with no malicious patterns. |
| examples/internal/proto/examplepb/stream_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/unannotated_echo_service.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for protobuf message definitions with no executable logic, network calls, filesystem access, or obfuscation. |
| examples/internal/proto/examplepb/unannotated_echo_service.pb.gw.go | safe | No malicious patterns detected; the code is standard generated gRPC-Gateway boilerplate for a reverse proxy service. |
| examples/internal/proto/examplepb/unannotated_echo_service_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/use_allof_for_refs.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code with no executable payloads, network calls, or filesystem access. |
| examples/internal/proto/examplepb/use_allof_for_refs.pb.gw.go | safe | This is a standard, auto-generated grpc-gateway reverse proxy file with no malicious patterns, obfuscation, external network calls, credential harvesting, or install-time execution. |
| examples/internal/proto/examplepb/use_allof_for_refs_grpc.pb.go | safe | This is a standard protoc-gen-go-grpc generated file containing only normal gRPC client/server scaffolding with no malicious patterns. |
| examples/internal/proto/examplepb/use_go_template.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code defining gRPC message types and descriptors without any dangerous behavior. |
| examples/internal/proto/examplepb/use_go_template.pb.gw.go | safe | No malicious patterns detected; this is standard generated gRPC-Gateway proxy code. |
| examples/internal/proto/examplepb/use_go_template_grpc.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/visibility_rule_echo_service.pb.go | safe | This is standard protoc-gen-go generated code for a gRPC visibility rule example; no malicious patterns, network activity, credential access, or dynamic execution were found. |
| examples/internal/proto/examplepb/visibility_rule_echo_service.pb.gw.go | safe | This is standard auto-generated grpc-gateway reverse proxy code with no malicious patterns, external calls, or suspicious behavior. |
| examples/internal/proto/examplepb/visibility_rule_echo_service_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/proto/examplepb/wrappers.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/examplepb/wrappers.pb.gw.go | safe | This is a standard gRPC-Gateway generated reverse proxy file with no malicious patterns, no dynamic code execution, no external network calls beyond the expected gRPC client, and no credential or environment harvesting. |
| examples/internal/proto/examplepb/wrappers_grpc.pb.go | safe | No malicious patterns detected in this protoc-generated gRPC service stub file. |
| examples/internal/proto/oneofenum/oneof_enum.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for protobuf enum and oneof message definitions with no network, filesystem, process, or dynamic execution activity. |
| examples/internal/proto/pathenum/path_enum.pb.go | safe | No malicious patterns detected |
| examples/internal/proto/standalone/unannotated_echo_service.pb.gw.go | safe | No malicious patterns detected; the file is a standard auto-generated gRPC-Gateway reverse proxy handler produced by protoc-gen-grpc-gateway with no obfuscation, exfiltration, persistence, or command execution code. |
| examples/internal/proto/sub/camel_case_message.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file with only protobuf runtime initialization and message accessors. |
| examples/internal/proto/sub/message.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns detected. |
| examples/internal/proto/sub2/message.pb.go | safe | No malicious patterns detected |
| examples/internal/server/a_bit_of_everything.go | safe | No malicious patterns detected; this is a benign example gRPC server implementation for the grpc-gateway project. |
| examples/internal/server/echo.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/server/fieldmask_helper.go | safe | The code implements a standard protobuf field mask application helper with no malicious patterns such as exfiltration, credential harvesting, code execution, network activity, or file system manipulation. |
| examples/internal/server/flow_combination.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/server/main.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/server/non_standard_names.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/server/responsebody.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/internal/server/unannotatedecho.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/casing/camel.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/codegenerator/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/codegenerator/parse_req.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/codegenerator/supported_features.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/descriptor/apiconfig/apiconfig.pb.go | safe | No malicious patterns detected |
| internal/descriptor/grpc_api_configuration.go | safe | No malicious patterns detected; the code parses YAML configuration files into protobuf structures and registers HTTP rules, with no exfiltration, credential harvesting, code execution, or other suspicious behavior. |
| internal/descriptor/openapi_configuration.go | safe | No malicious patterns detected; the code performs standard YAML-to-protobuf configuration parsing and file reading without exfiltration, credential harvesting, dynamic execution, or shell/network activity. |
| internal/descriptor/openapiconfig/openapiconfig.pb.go | safe | No malicious patterns detected in this auto-generated protobuf Go code; it contains only standard protobuf message definitions and initialization logic with no network, filesystem, or code execution activity. |
| internal/descriptor/registry.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/descriptor/services.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/descriptor/types.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/generator/generator.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/httprule/compile.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/httprule/fuzz.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/httprule/parse.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/httprule/types.go | safe | Cleared by Jev triage; no further analysis needed |
| openapiv3-merge/internal/merge/merge.go | safe | Cleared by Jev triage; no further analysis needed |
| openapiv3-merge/main.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-grpc-gateway/internal/gengateway/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-grpc-gateway/internal/gengateway/generator.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-grpc-gateway/internal/gengateway/template.go | safe | This is a legitimate grpc-gateway code generator template file with no malicious patterns, network calls, credential harvesting, or dynamic code execution beyond standard Go text/template usage. |
| protoc-gen-grpc-gateway/main.go | safe | No malicious patterns detected; this is a standard protoc plugin entry point with no network, process, or filesystem exfiltration behavior. |
| protoc-gen-openapiv2/internal/genopenapi/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/format.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/generator.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/helpers.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/helpers_go111_old.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/naming.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/internal/genopenapi/types.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv2/main.go | safe | This is a legitimate protoc plugin (protoc-gen-openapiv2) from grpc-gateway; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time hooks were detected. |
| protoc-gen-openapiv2/options/annotations.pb.go | safe | This is standard protoc-gen-go generated code registering protobuf extension descriptors; no malicious patterns, network activity, credential access, or dynamic execution were found. |
| protoc-gen-openapiv2/options/annotations_protoopaque.pb.go | safe | No malicious patterns detected in this auto-generated protobuf descriptor file, which only registers gRPC-Gateway OpenAPI extension types. |
| protoc-gen-openapiv3/internal/genopenapi/annotations.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/comments.go | safe | No malicious patterns detected; this Go file performs legitimate protobuf comment extraction with no network, filesystem, process, or dynamic execution behavior. |
| protoc-gen-openapiv3/internal/genopenapi/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/generator.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/naming.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/operation.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/path.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/schema.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/types.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/visibility.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/internal/genopenapi/wkt.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/main.go | safe | Cleared by Jev triage; no further analysis needed |
| protoc-gen-openapiv3/options/annotations.pb.go | safe | No malicious patterns detected; the file is standard generated protobuf code defining gRPC-Gateway OpenAPI v3 extension descriptors with no network, filesystem, process, or dynamic execution behavior. |
| protoc-gen-openapiv3/options/annotations_protoopaque.pb.go | safe | No malicious patterns detected |
| protoc-gen-openapiv3/options/openapiv3.pb.go | safe | This is a standard protoc-gen-go generated file defining OpenAPI v3 option message types with no executable logic, network access, file operations, or other malicious patterns. |
| protoc-gen-openapiv3/options/openapiv3_protoopaque.pb.go | safe | This is a standard protoc-gen-go generated file containing only protobuf message definitions and reflection boilerplate for OpenAPI v3 options, with no execution, network, filesystem, or obfuscated behavior beyond normal proto init registration. |
| runtime/context.go | safe | No malicious patterns detected |
| runtime/convert.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/errors.go | safe | No malicious patterns detected; the code is a standard gRPC-Gateway error handling implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process activity. |
| runtime/fieldmask.go | safe | No malicious patterns detected; the code is a legitimate protobuf field mask utility with no network, filesystem, process, or dynamic execution activity. |
| runtime/handler.go | safe | No malicious patterns detected; the code is a standard gRPC-Gateway HTTP response forwarding handler from the grpc-gateway runtime package. |
| runtime/internal/examplepb/example.pb.go | safe | No malicious patterns detected |
| runtime/internal/examplepb/non_standard_names.pb.go | safe | This is standard protoc-gen-go generated code for Protocol Buffer message definitions with no malicious patterns, network calls, file access, or dynamic execution. |
| runtime/internal/examplepb/non_standard_names_grpc.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go-grpc generated code implementing gRPC client and server stubs for the NonStandardService. |
| runtime/internal/examplepb/proto2.pb.go | safe | This is standard auto-generated protobuf Go code from the grpc-gateway project with no malicious patterns, network calls, or suspicious behavior. |
| runtime/internal/examplepb/proto3.pb.go | safe | This is a standard protoc-gen-go generated file containing only protocol buffer message definitions and serialization logic, with no malicious patterns detected. |
| runtime/marshal_httpbodyproto.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/marshal_json.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/marshal_jsonpb.go | safe | No malicious patterns detected; this is legitimate gRPC-Gateway runtime JSON marshaling code using protojson and reflection for protobuf serialization. |
| runtime/marshal_proto.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/marshaler.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/marshaler_registry.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/mux.go | safe | No malicious patterns detected in the provided grpc-gateway ServeMux source code; it is a legitimate HTTP/gRPC routing multiplexer with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| runtime/pattern.go | safe | No malicious patterns detected |
| runtime/proto2_convert.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/query.go | safe | This file contains standard gRPC-Gateway query parameter parsing logic with no malicious patterns, network calls, credential access, or dynamic code execution. |
| utilities/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| utilities/pattern.go | safe | Cleared by Jev triage; no further analysis needed |
| utilities/readerfactory.go | safe | Cleared by Jev triage; no further analysis needed |
| utilities/string_array_flag.go | safe | Cleared by Jev triage; no further analysis needed |
| utilities/trie.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/grpc-ecosystem/grpc-gateway/v2 safe to use?
No confirmed malware was found in github.com/grpc-ecosystem/grpc-gateway/v2@v2.30.0, but the review flagged 3 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/grpc-ecosystem/grpc-gateway/v2 contain malware?
No malware was identified in github.com/grpc-ecosystem/grpc-gateway/v2@v2.30.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/grpc-ecosystem/grpc-gateway/v2 checked?
Togoder Security downloaded the published Go package and had an AI model read its 362 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/grpc-ecosystem/grpc-gateway/v2 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/grpc-ecosystem/grpc-gateway/v2@v2.30.0, cost nothing.