Togoder security

Go package security report

github.com/stretchr/testify@v1.12.1 security report

Risky patterns found that deserve a look.

Needs review Version v1.12.1 Files reviewed 39 Size 460.3 KB Scanned

Summary

Togoder Security scanned the Go package github.com/stretchr/testify@v1.12.1 on Oct 5, 2026. An AI review of 39 source files produced 1 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
9
low

Findings 10

medium

Unsafe reflection / memory manipulation

NPS-6F43551331D9

The code uses Go's unsafe package to access and modify the internal flag field of reflect.Value, bypassing Go's type safety and readonly protections. This is a deliberate circumvention of safety mechanisms to access unexported fields. While the stated purpose is for pretty-printing, this pattern could be weaponized to read sensitive in-memory data that would otherwise be inaccessible.

internal/spew/bypass.go:78
low

File system access

NPS-FF58E4EEB903

Reads and (indirectly) rewrites README.md in the current working directory. This is within the stated scope of the tool (formatting Go blocks in README.md), so it stays within package scope rather than reaching into credential files or user directories.

_readme-gofmt/main.go:43
low

Process execution

NPS-673626CE39DD

The code uses os/exec to invoke external commands (gofmt and diff) via exec.Command. While these are the intended, documented behavior of the tool (running gofmt -s on README code blocks and showing a diff), spawning external processes is listed as a red flag. Here the commands are hardcoded to well-known binaries located via exec.LookPath, no shell is used, and no user-controlled or remote input feeds the command arguments, so the risk is limited to the tool's legitimate purpose.

_readme-gofmt/main.go:60
low

Process execution

NPS-EF1822A75333

A second external process 'diff' is launched with fixed arguments ('-a', '-u', 'README.md', '-') to display a diff of the modified file. Again hardcoded, no shell interpolation, and used for legitimate reporting. Included as a lower-severity observation.

_readme-gofmt/main.go:84
low

Unsafe reflection and type conversion

NPS-00AF93F2362D

Functions like copyExportedFields, ObjectsAreEqualValues, and others use extensive reflection. While normal for a testing library, reflection over untrusted types can cause panics; code guards with recover in several places.

assert/assertions.go
low

Dynamic code execution (regexp compilation)

NPS-34DCCECA98B3

matchRegexp uses regexp.MustCompile on the provided rx argument when it isn't already a *regexp.Regexp. Compiling attacker-controlled patterns can cause panics or resource exhaustion (though this is expected behavior for a regex assertion helper).

assert/assertions.go:1102
low

File system manipulation (Lstat)

NPS-054F94476B6D

FileExists, NoFileExists, DirExists, and NoDirExists functions call os.Lstat with a user-provided path. This is a standard testing utility but could be misused to probe filesystem paths if the arguments come from an untrusted source.

assert/assertions.go:1163
low

YAML/JSON deserialization of untrusted input

NPS-6C9BA12456CE

YAMLEq and JSONEq unmarshal arbitrary strings provided by the caller. yaml.Unmarshal in some libraries can trigger unsafe behavior; here it is a wrapper around go.yaml.in/yaml/v3, so risk depends on the wrapped library, not this file.

assert/assertions.go:1230
low

Build-tag gated unsafe access

NPS-849932A106C8

The file is compiled only when certain build tags are absent (not js, not appengine, not safe, not disableunsafe). This means the unsafe behavior is silently included in standard builds, and consumers may not realize the package manipulates memory unsafely. However, this is documented in the source comments and is the established behavior of the davecgh/go-spew package.

internal/spew/bypass.go:18
low

Runtime introspection and panic on unexpected environment

NPS-97C7539CC13C

The init() function performs deep runtime introspection of the reflect package's internal layout and panics if it cannot verify known flag bit layouts. This is defensive but indicates tight coupling to Go internals, which can break or behave unexpectedly on different runtime versions.

internal/spew/bypass.go:97

Files reviewed

FileVerdictWhat the reviewer saw
_readme-gofmt/main.go medium The tool invokes gofmt and diff via os/exec and edits README.md, but all commands and paths are hardcoded and consistent with its documented purpose; no exfiltration, credential harvesting, obfuscation, or backdoor behavior is present.
assert/assertions.go medium This is the well-known testify assert package; no data exfiltration, credential harvesting, obfuscation, backdoors, or install-time hooks were found, though it uses filesystem Lstat, regexp compilation, reflection and deserialization that require untrusted-input caution.
internal/spew/bypass.go medium This is a known, legitimate pretty-printing library that deliberately uses unsafe reflection to access unexported fields; no malicious patterns (exfiltration, credential theft, backdoors, network calls, or process spawning) are present, though the unsafe memory manipulation warrants a warning-level classification.
assert/assertion_compare.go safe Cleared by Jev triage; no further analysis needed
assert/assertion_format.go safe This is a standard generated file from the testify assertion library containing only assertion wrapper functions with no malicious patterns detected.
assert/assertion_forward.go safe This is a generated Testify assertion forwarding file containing only standard test helper pass-through methods with no malicious, obfuscated, or exfiltrating code.
assert/assertion_order.go safe Cleared by Jev triage; no further analysis needed
assert/doc.go safe Cleared by Jev triage; no further analysis needed
assert/errors.go safe Cleared by Jev triage; no further analysis needed
assert/forward_assertions.go safe No malicious patterns detected; this is a standard Go testing assertion helper with no network, filesystem, or process execution behavior.
assert/http_assertions.go safe Cleared by Jev triage; no further analysis needed
assert/internal/unsafetests/doc.go safe No malicious patterns detected
assert/yaml/yaml_custom.go safe This is a legitimate pluggable YAML interface using build tags, with no malicious patterns such as exfiltration, code execution, or credential harvesting.
assert/yaml/yaml_default.go safe Cleared by Jev triage; no further analysis needed
assert/yaml/yaml_fail.go safe Cleared by Jev triage; no further analysis needed
doc.go safe Cleared by Jev triage; no further analysis needed
http/doc.go safe Cleared by Jev triage; no further analysis needed
http/test_response_writer.go safe Cleared by Jev triage; no further analysis needed
http/test_round_tripper.go safe Cleared by Jev triage; no further analysis needed
internal/difflib/difflib.go safe Cleared by Jev triage; no further analysis needed
internal/spew/bypasssafe.go safe Cleared by Jev triage; no further analysis needed
internal/spew/common.go safe No malicious patterns detected
internal/spew/config.go safe Cleared by Jev triage; no further analysis needed
internal/spew/doc.go safe Cleared by Jev triage; no further analysis needed
internal/spew/dump.go safe No malicious patterns detected
Show 14 more files
FileVerdictWhat the reviewer saw
internal/spew/format.go safe Cleared by Jev triage; no further analysis needed
internal/spew/spew.go safe Cleared by Jev triage; no further analysis needed
internal/spew/testdata/dumpcgo.go safe No malicious patterns detected; this is a benign cgo test fixture gated behind build tags that only exposes test data.
mock/doc.go safe Cleared by Jev triage; no further analysis needed
mock/mock.go safe This is the legitimate testify/mock package source code with no malicious patterns, no network activity, no credential harvesting, and no dynamic code execution.
require/doc.go safe Cleared by Jev triage; no further analysis needed
require/forward_requirements.go safe No malicious patterns detected; the file contains only a simple assertion wrapper and a code generation directive with no execution, network, or filesystem concerns.
require/require.go safe No malicious patterns detected; this is a standard generated Testify require wrapper package with no I/O, network, execution, or credential access.
require/require_forward.go safe No malicious patterns detected; this is standard generated assertion wrapper code for the testify/require package.
require/requirements.go safe No malicious patterns detected
suite/doc.go safe Cleared by Jev triage; no further analysis needed
suite/interfaces.go safe Cleared by Jev triage; no further analysis needed
suite/stats.go safe Cleared by Jev triage; no further analysis needed
suite/suite.go safe No malicious patterns detected; the file is the standard testify testing suite with reflection-based test execution and no exfiltration, credential harvesting, or obfuscated code.

Frequently asked questions

Is github.com/stretchr/testify safe to use?

No confirmed malware was found in github.com/stretchr/testify@v1.12.1, but the review flagged 1 medium, 9 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/stretchr/testify contain malware?

No malware was identified in github.com/stretchr/testify@v1.12.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/stretchr/testify checked?

Togoder Security downloaded the published Go package and had an AI model read its 39 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/stretchr/testify together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/stretchr/testify@v1.12.1, cost nothing.

Related security reports