Togoder security

Go package security report

github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible security report

Risky patterns found that deserve a look.

Needs review Version v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible Files reviewed 25 Size 48.9 KB Scanned

Summary

Togoder Security scanned the Go package github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible on Oct 5, 2026. An AI review of 25 source files produced 4 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
9
low

Findings 13

medium

SQL Injection via Table Name

NPS-3EE0E5ED59DE

All dialect methods construct SQL by directly interpolating TableName() into SQL strings via fmt.Sprintf, without quoting or escaping. If an application sets a custom table name from untrusted input, this enables SQL injection. This is a latent vulnerability in a widely used migration library (goose).

dialect.go:43
medium

SQL Injection via Table Name (repeated)

NPS-633FAEA158F6

The same TableName() interpolation pattern is repeated across every dialect's createVersionTableSQL, insertVersionSQL, dbVersionQuery, migrationSQL, and deleteVersionSQL methods (Postgres, MySQL, MSSQL, SQLite3, Redshift, TiDB). Any dialect selected by SetDialect inherits this pattern.

dialect.go:82
medium

Improper error handling

NPS-4F9E8FFA3026

In dbMigrationsStatus, when GetDialect().dbVersionQuery(db) returns an error, the function returns an empty map and nil error instead of propagating the error. This could mask database connection or query failures, leading to unintended behavior such as skipping rollback operations silently.

reset.go:39
medium

Potential destructive operation without error propagation

NPS-D2D8DB206C3B

The Reset function rolls back all migrations. If dbMigrationsStatus fails to retrieve statuses correctly (due to the swallowed error above), it may proceed with an empty status map and fail to roll back any migrations, or in other scenarios could incorrectly roll back. This is a logic flaw that could leave the database in an inconsistent state.

reset.go:44
low

Global Mutable Dialect State

NPS-51ECCFDDD10D

SetDialect mutates a package-level variable (dialect) with no synchronization. Concurrent callers could race and cause inconsistent behavior, and any code in the process can silently swap the dialect. This is a design/thread-safety concern rather than a direct exploit.

dialect.go:24
low

File system manipulation

NPS-0013BC56912B

The code renames files using os.Rename, which could modify files outside the intended migration directory if the newPath is constructed in a way that escapes the directory (e.g., via path traversal). However, the newPath is derived from oldPath by replacing the version number with a formatted version, and the oldPath comes from CollectMigrations which presumably lists files within dir. This is likely intended functionality for fixing migration filenames, but could be risky if dir is user-controlled or if symlinks are present.

fix.go
low

Potential path traversal

NPS-DC8597A95887

The newPath is built using strings.Replace on the oldPath, which includes the directory. If the version number appears in the directory portion, it could inadvertently rename the directory or cause unexpected path changes. Additionally, if the migration version is negative or has unusual formatting, the replacement might not match, but the code would still attempt to rename. This is not malicious per se, but could lead to unintended file operations.

fix.go
low

Deprecated unsafe package

NPS-1BCA2D5B8350

Import of 'github.com/pkg/errors' which is deprecated and no longer maintained. While not malicious, using deprecated packages introduces security risks as vulnerabilities may not be patched.

migration.go:9
low

Unsafe error formatting

NPS-50B70FAF30EB

The String() method uses fmt.Sprintf(m.Source) where m.Source is used directly as the format string. If m.Source contains format specifiers (e.g., %s, %n, %v), this could lead to unexpected behavior or potentially leak panic information. In Go, this is flagged by go vet as a potential bug. While not directly malicious, it's poor practice and could be exploited if migration source paths are attacker-controlled.

migration.go:33
low

Potential path traversal / information disclosure

NPS-3AB41AD2B0F5

The code uses strings.Split(m.Source, 'migrations') and accesses x[1][1:] without bounds checking. If m.Source does not contain 'migrations', this will cause a panic (index out of range). Similarly, in NumericComponent, strings.Split(name, 'migrations') followed by accessing versionFolder[1][1:] could panic. This is a robustness issue that could be triggered by an attacker supplying a crafted migration path, potentially causing denial of service.

migration.go:68
low

Memory allocation from sync.Pool

NPS-849B31A68ECE

The code uses sync.Pool to reuse a 4MB buffer for scanning. This is standard for performance; no malicious intent.

sql_parser.go:30
low

Regular expression match on empty lines

NPS-2D3B7D839126

The regex ^\s*$ is used to skip empty lines; no security impact.

sql_parser.go:37
low

Logging of migration content

NPS-56E015EFC23D

When verbose mode is enabled, the parser logs SQL lines. This could leak sensitive SQL content if verbose logging is enabled in an insecure environment, but it is intentional for debugging and not a malicious pattern.

sql_parser.go:76

Files reviewed

FileVerdictWhat the reviewer saw
dialect.go medium The file contains no malicious behaviors (no exfiltration, credential harvesting, obfuscation, mining, backdoors, or process execution), but it exhibits a latent SQL-injection pattern via unquoted TableName() interpolation that could be exploitable in downstream applications.
fix.go medium The code performs file renaming operations within the migration directory, which is likely legitimate but could pose a low risk if input paths are not properly validated.
migration.go medium No malicious patterns detected; code is a legitimate database migration library (goose) with minor code quality issues.
reset.go medium The code contains no malicious patterns but has error handling flaws that could lead to unintended database state during migration rollback.
cmd/goose/driver_mssql.go safe Cleared by Jev triage; no further analysis needed
cmd/goose/driver_mysql.go safe Cleared by Jev triage; no further analysis needed
cmd/goose/driver_no_mysql.go safe Cleared by Jev triage; no further analysis needed
cmd/goose/driver_postgres.go safe Cleared by Jev triage; no further analysis needed
cmd/goose/driver_sqlite3.go safe No malicious patterns detected; this file only imports the go-sqlite3 driver via a blank import for side effects.
cmd/goose/main.go safe No malicious patterns detected; the file is a straightforward CLI entry point for the goose database migration tool.
create.go safe No malicious patterns detected; the code generates local Go migration files using standard library calls without any network, credential, or process execution activity.
db.go safe No malicious patterns detected
down.go safe Cleared by Jev triage; no further analysis needed
examples/go-migrations/00002_rename_root.go safe No malicious patterns detected; the code is a standard database migration for renaming a username and does not exhibit any security concerns.
examples/go-migrations/main.go safe No malicious patterns detected
goose.go safe No malicious patterns detected in the analyzed Go source file; it is a benign database migration tool with standard command dispatch logic.
helpers.go safe No malicious patterns detected; the code is a benign string case conversion utility.
log.go safe No malicious patterns detected
migrate.go safe No malicious patterns detected; the code is a standard database migration library with no external network, credential, or exec operations.
migration_sql.go safe No malicious patterns detected; the code is a legitimate database migration utility for the goose library.
redo.go safe Cleared by Jev triage; no further analysis needed
sql_parser.go safe The code is a benign SQL migration parser with no malicious patterns; it only processes input from an io.Reader and does not perform network, filesystem, or process operations.
status.go safe No malicious patterns detected
up.go safe The code is a standard database migration library (goose) with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
version.go safe No malicious patterns detected

Frequently asked questions

Is github.com/thrasher-corp/goose safe to use?

No confirmed malware was found in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible, but the review flagged 4 medium, 9 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/thrasher-corp/goose contain malware?

No malware was identified in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/thrasher-corp/goose checked?

Togoder Security downloaded the published Go package and had an AI model read its 25 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/thrasher-corp/goose together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible, cost nothing.

Related security reports