Summary
Togoder Security scanned the Go package github.com/stretchr/testify@v1.12.1 on Oct 5, 2026. An AI review of 39 source files produced 1 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 10
Unsafe reflection / memory manipulation
NPS-6F43551331D9
The code uses Go's unsafe package to access and modify the internal flag field of reflect.Value, bypassing Go's type safety and readonly protections. This is a deliberate circumvention of safety mechanisms to access unexported fields. While the stated purpose is for pretty-printing, this pattern could be weaponized to read sensitive in-memory data that would otherwise be inaccessible.
File system access
NPS-FF58E4EEB903
Reads and (indirectly) rewrites README.md in the current working directory. This is within the stated scope of the tool (formatting Go blocks in README.md), so it stays within package scope rather than reaching into credential files or user directories.
Process execution
NPS-673626CE39DD
The code uses os/exec to invoke external commands (gofmt and diff) via exec.Command. While these are the intended, documented behavior of the tool (running gofmt -s on README code blocks and showing a diff), spawning external processes is listed as a red flag. Here the commands are hardcoded to well-known binaries located via exec.LookPath, no shell is used, and no user-controlled or remote input feeds the command arguments, so the risk is limited to the tool's legitimate purpose.
Process execution
NPS-EF1822A75333
A second external process 'diff' is launched with fixed arguments ('-a', '-u', 'README.md', '-') to display a diff of the modified file. Again hardcoded, no shell interpolation, and used for legitimate reporting. Included as a lower-severity observation.
Unsafe reflection and type conversion
NPS-00AF93F2362D
Functions like copyExportedFields, ObjectsAreEqualValues, and others use extensive reflection. While normal for a testing library, reflection over untrusted types can cause panics; code guards with recover in several places.
Dynamic code execution (regexp compilation)
NPS-34DCCECA98B3
matchRegexp uses regexp.MustCompile on the provided rx argument when it isn't already a *regexp.Regexp. Compiling attacker-controlled patterns can cause panics or resource exhaustion (though this is expected behavior for a regex assertion helper).
File system manipulation (Lstat)
NPS-054F94476B6D
FileExists, NoFileExists, DirExists, and NoDirExists functions call os.Lstat with a user-provided path. This is a standard testing utility but could be misused to probe filesystem paths if the arguments come from an untrusted source.
YAML/JSON deserialization of untrusted input
NPS-6C9BA12456CE
YAMLEq and JSONEq unmarshal arbitrary strings provided by the caller. yaml.Unmarshal in some libraries can trigger unsafe behavior; here it is a wrapper around go.yaml.in/yaml/v3, so risk depends on the wrapped library, not this file.
Build-tag gated unsafe access
NPS-849932A106C8
The file is compiled only when certain build tags are absent (not js, not appengine, not safe, not disableunsafe). This means the unsafe behavior is silently included in standard builds, and consumers may not realize the package manipulates memory unsafely. However, this is documented in the source comments and is the established behavior of the davecgh/go-spew package.
Runtime introspection and panic on unexpected environment
NPS-97C7539CC13C
The init() function performs deep runtime introspection of the reflect package's internal layout and panics if it cannot verify known flag bit layouts. This is defensive but indicates tight coupling to Go internals, which can break or behave unexpectedly on different runtime versions.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _readme-gofmt/main.go | medium | The tool invokes gofmt and diff via os/exec and edits README.md, but all commands and paths are hardcoded and consistent with its documented purpose; no exfiltration, credential harvesting, obfuscation, or backdoor behavior is present. |
| assert/assertions.go | medium | This is the well-known testify assert package; no data exfiltration, credential harvesting, obfuscation, backdoors, or install-time hooks were found, though it uses filesystem Lstat, regexp compilation, reflection and deserialization that require untrusted-input caution. |
| internal/spew/bypass.go | medium | This is a known, legitimate pretty-printing library that deliberately uses unsafe reflection to access unexported fields; no malicious patterns (exfiltration, credential theft, backdoors, network calls, or process spawning) are present, though the unsafe memory manipulation warrants a warning-level classification. |
| assert/assertion_compare.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/assertion_format.go | safe | This is a standard generated file from the testify assertion library containing only assertion wrapper functions with no malicious patterns detected. |
| assert/assertion_forward.go | safe | This is a generated Testify assertion forwarding file containing only standard test helper pass-through methods with no malicious, obfuscated, or exfiltrating code. |
| assert/assertion_order.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/forward_assertions.go | safe | No malicious patterns detected; this is a standard Go testing assertion helper with no network, filesystem, or process execution behavior. |
| assert/http_assertions.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/internal/unsafetests/doc.go | safe | No malicious patterns detected |
| assert/yaml/yaml_custom.go | safe | This is a legitimate pluggable YAML interface using build tags, with no malicious patterns such as exfiltration, code execution, or credential harvesting. |
| assert/yaml/yaml_default.go | safe | Cleared by Jev triage; no further analysis needed |
| assert/yaml/yaml_fail.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| http/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| http/test_response_writer.go | safe | Cleared by Jev triage; no further analysis needed |
| http/test_round_tripper.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/difflib/difflib.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/bypasssafe.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/common.go | safe | No malicious patterns detected |
| internal/spew/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/dump.go | safe | No malicious patterns detected |
Show 14 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/spew/format.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/spew.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/spew/testdata/dumpcgo.go | safe | No malicious patterns detected; this is a benign cgo test fixture gated behind build tags that only exposes test data. |
| mock/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| mock/mock.go | safe | This is the legitimate testify/mock package source code with no malicious patterns, no network activity, no credential harvesting, and no dynamic code execution. |
| require/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| require/forward_requirements.go | safe | No malicious patterns detected; the file contains only a simple assertion wrapper and a code generation directive with no execution, network, or filesystem concerns. |
| require/require.go | safe | No malicious patterns detected; this is a standard generated Testify require wrapper package with no I/O, network, execution, or credential access. |
| require/require_forward.go | safe | No malicious patterns detected; this is standard generated assertion wrapper code for the testify/require package. |
| require/requirements.go | safe | No malicious patterns detected |
| suite/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| suite/interfaces.go | safe | Cleared by Jev triage; no further analysis needed |
| suite/stats.go | safe | Cleared by Jev triage; no further analysis needed |
| suite/suite.go | safe | No malicious patterns detected; the file is the standard testify testing suite with reflection-based test execution and no exfiltration, credential harvesting, or obfuscated code. |
Frequently asked questions
Is github.com/stretchr/testify safe to use?
No confirmed malware was found in github.com/stretchr/testify@v1.12.1, but the review flagged 1 medium, 9 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/stretchr/testify contain malware?
No malware was identified in github.com/stretchr/testify@v1.12.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/stretchr/testify checked?
Togoder Security downloaded the published Go package and had an AI model read its 39 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/stretchr/testify together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/stretchr/testify@v1.12.1, cost nothing.