Togoder security

Go package security report

golang.org/x/net@v0.59.0 security report

Risky patterns found that deserve a look.

Needs review Version v0.59.0 Files reviewed 513 Size 2.9 MB Scanned

Summary

Togoder Security scanned the Go package golang.org/x/net@v0.59.0 on Oct 5, 2026. An AI review of 513 source files produced 11 medium, 42 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
11
medium
42
low

Findings 53

medium

Deprecated package with known buffering concern

NPS-A24800D977F5

The NewHandler documentation explicitly warns that the first request on an h2c connection is read entirely into memory before the Handler is called, which can lead to unbounded memory consumption if not wrapped in http.MaxBytesHandler. This is a documented design limitation rather than an intentional backdoor, but it can be abused for denial-of-service.

http2/h2c/h2c.go
medium

Insecure TLS configuration

NPS-8674AEB880B5

The -insecure flag sets InsecureSkipVerify: true in the tls.Config, disabling certificate validation. While this is intentional for a diagnostic tool, it allows man-in-the-middle attacks if used carelessly.

http2/h2i/h2i.go:191
medium

Hostname verification bypass

NPS-C6B5D430223A

When -insecure is set, VerifyHostname is explicitly skipped, further weakening TLS security and allowing connections to servers with mismatched certificates.

http2/h2i/h2i.go:218
medium

Unsafe linkname directive

NPS-3751525576EC

The file uses //go:linkname to link to unexported functions in the net/http_test package (registerHTTP3Server and registerHTTP3Transport). This mechanism bypasses Go's type safety and package encapsulation, and is generally discouraged in production code. It can be used to access internal APIs not intended for public use. While the apparent purpose is to allow tests to pass options structs to registration functions, this pattern introduces fragility and potential for abuse if the target package changes or if the linkname is manipulated maliciously.

http3/http3.go:12
medium

Insecure TLS configuration

NPS-B46D5F7211C3

TLSConfig sets InsecureSkipVerify: true, disabling certificate verification. This is expected for interoperability testing but would be dangerous in production and could facilitate MITM attacks if this code were reused or run outside the interop test context.

internal/quic/cmd/interop/main.go:47
medium

File system access from environment-controlled paths

NPS-44E37CDA3E5C

The -root, -output, and -qlog flags control where files are read from and written to. Although paths are validated with filepath.IsLocal on request paths, the root/output directories themselves are attacker-influenced and used for file operations, which could write arbitrary files to unintended locations if defaults are empty.

internal/quic/cmd/interop/main.go:189
medium

unsafe pointer usage

NPS-BFBD4F8F862B

The code uses unsafe.Pointer to cast byte slices directly into cmsghdr structs in MarshalHeader, ParseHeader, Marshal, and Parse methods. While this is standard practice in Go's low-level networking libraries and appears legitimate, incorrect bounds checking could lead to memory corruption or out-of-bounds reads. The parsing logic in Parse() does include numerous length validations, but direct memory reinterpretation via unsafe.Pointer is inherently risky.

internal/socket/socket.go:137
medium

Remote Code Generation

NPS-32A2EC148C45

The parseICMPv4Parameters function processes XML from a remote source and emits Go source code derived from remote descriptions. If the remote server or MITM attacker supplied malicious XML, the generated code could contain unexpected constants, though format.Source would likely reject syntactically invalid code. This represents a potential supply chain risk.

ipv4/gen.go:110
medium

network_request

NPS-242E0134F0A8

The geniana function performs an unauthenticated HTTP GET request to a hardcoded external URL (https://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xml) and parses the response. While this is a legitimate IANA registry, fetching and processing remote XML without integrity verification (e.g., signature or hash check) at generation time could allow a compromised or spoofed response to inject malicious constants into generated code.

ipv6/gen.go:77
medium

authorization depends on unverified RemoteAddr

NPS-ABB682E6F530

AuthRequest decides access solely based on req.RemoteAddr (host portion). Behind a reverse proxy or when a client can influence RemoteAddr (e.g., X-Forwarded-For misconfiguration, unix sockets, or non-TCP transports), remote requests could appear to originate from localhost, bypassing the only access control. The package provides no additional token/secret check.

trace/trace.go:100
medium

debug/pprof-style information disclosure endpoint

NPS-4AF8F433CF02

The package registers HTTP handlers on the DefaultServeMux at /debug/requests and /debug/events and exposes internal trace data (titles, events, IDs, timing, call stacks) via an HTML page. Although AuthRequest defaults to allowing only localhost (letting an operator serve it on a private interface), the handler is bound globally and inherits any external-facing listener or reverse proxy using DefaultServeMux, which could expose sensitive diagnostic data (URL paths, error messages, IDs, stack traces) to remote clients if the default is customized or if RemoteAddr is spoofed in a proxy configuration.

trace/trace.go:184
low

debug utility

NPS-0D43D96459CB

This file is a defensive debug-only utility that tracks goroutine IDs for internal consistency checks. It reads an environment variable DEBUG_HTTP2_GOROUTINES to enable debugging and uses runtime.Stack to parse goroutine IDs. No network, file system, process spawning, or obfuscated code is present.

http2/gotrack.go
low

Use of GODEBUG environment variable

NPS-DF0E587DF796

The init() function reads the GODEBUG environment variable to enable verbose HTTP/2 logging. This is a standard Go debugging mechanism, not credential harvesting, but it is an environment variable read at import time.

http2/h2c/h2c.go:48
low

External network connections controlled by flags

NPS-AC73B8BA475C

The tool dials arbitrary hosts/ports specified on the command line, including a -dial flag that permits connecting to a different SNI name. This is expected behavior for an interactive HTTP/2 client but could be abused if the binary is invoked with untrusted arguments.

http2/h2i/h2i.go:200
low

Terminal raw mode manipulation

NPS-3BC7585DBBA2

The program sets the terminal to raw mode via term.MakeRaw, capturing all keystrokes. This is standard for interactive consoles but could theoretically capture sensitive input if the user types credentials.

http2/h2i/h2i.go:235
low

import time code execution

NPS-3F97569ADAB0

The init() function runs at import time, which is normal for Go packages. It only configures logging and protocol flags based on environment variables and does not perform any malicious actions.

http2/http2.go:40
low

environment variable usage

NPS-C2B6FA2A7DA7

The init() function reads the GODEBUG environment variable to enable verbose logging and extended CONNECT protocol. This is a standard Go debugging mechanism, not credential harvesting or exfiltration. It only checks for specific substrings (http2debug=1, http2debug=2, http2xconnect=1) and does not send data externally.

http2/http2.go:41
low

Resource management

NPS-7019C1C94BE5

In writeGoAway.writeFrame, the error returned by ctx.Flush() is deliberately ignored. This is intentional and documented ('ignore error: we're hanging up on them anyway') and does not introduce a security vulnerability.

http2/write.go:96
low

Panic on unexpected input

NPS-BEC54F280BC9

writeResHeaders.writeFrame and writePushPromise.writeFrame panic if the HPACK header block is empty. The code comments suggest this should be unreachable, but a panic could be triggered by unusual header state, potentially causing a denial of service. This is likely an internal invariant rather than an attacker-controlled path.

http2/write.go:208
low

Use of reflection for struct copying

NPS-D74D7130D527

The shallowStructCopy function uses reflection to copy fields from one struct to another. While this is a legitimate technique, it can be misused to bypass access controls or type checks. However, in this context, it enforces that all fields are exported and assignable, which mitigates some risks. Still, reflection-based manipulation can be a vector for unexpected behavior if the source or destination types are not fully trusted.

http3/http3.go:31
low

Potential panic on invalid input

NPS-E2BA9CB90092

The writeSettings function notes that settings values that don't fit in a QUIC varint will panic when sizeVarint is called. This is a robustness issue but not malicious; it's a standard Go library implementation where callers are expected to provide valid values. It could lead to a denial of service if an attacker can control the settings values, but the function is internal and likely called with trusted constants.

internal/http3/settings.go:23
low

network_fetch_in_generate

NPS-9C2B526BE524

The program fetches XML registries over HTTPS from www.iana.org only during 'go generate' and writes generated Go constants locally. These are expected, bounded, and not malicious.

internal/iana/gen.go:44
low

file_write

NPS-193499EF3699

Writes generated output to 'const.go' in the current directory. This is intended generator behavior, not package runtime behavior, and is gated behind the 'ignore' build tag.

internal/iana/gen.go:65
low

Environment variable harvesting

NPS-54BAAE9C672E

Reads SSLKEYLOGFILE environment variable and writes TLS session keys to the specified file, which could leak sensitive secrets if the env var is set in an untrusted environment.

internal/quic/cmd/interop/main.go:70
low

Unsanitized file path usage

NPS-B5B84BD821E9

serveReq joins *root with the request path after only checking filepath.IsLocal. While IsLocal blocks traversal, it still permits opening arbitrary local files under root, which is the intended server behavior but is a file-system exposure surface.

internal/quic/cmd/interop/main.go:197
low

unsafe pointer usage

NPS-4119D285D30D

The set method uses unsafe.Pointer to obtain a pointer to the first byte of the slice. This is a standard pattern in Go networking libraries (e.g., golang.org/x/net) for constructing iovec structures for syscalls like readv/writev. The pointer is set to &b[0], which is safe because the length check ensures the slice is non-empty. No memory is accessed beyond the slice bounds.

internal/socket/iovec_32bit.go:17
low

unsafe pointer usage

NPS-7C00CC236164

This file uses the unsafe package to convert a byte slice into a raw pointer for an I/O vector (iovec). While the pointer is only stored and length is bounded by the slice length, any future misuse could lead to memory safety issues. The code is legitimate and standard for the golang.org/x/sys/unix package.

internal/socket/iovec_64bit.go:16
low

low-level socket control message manipulation

NPS-79D9DEBBA493

The ControlMessage type provides direct kernel-level sendmsg/recvmsg control message marshaling and parsing. Malformed control messages can be used in exploits (e.g., CMSG parsing bugs), though this appears to be legitimate golang.org/x/net code that mirrors upstream Go source.

internal/socket/socket.go:88
low

system call interface

NPS-600308445C31

Methods RecvMsg, SendMsg, RecvMsgs, SendMsgs expose raw recvmsg/sendmsg/recvmmsg/sendmmsg syscalls to callers with caller-controlled flags. This is expected functionality for a socket utility package, but provides a powerful interface that could be misused by dependents.

internal/socket/socket.go:253
low

No evidence of malicious behavior

NPS-D7103D02D327

The code performs standard socket option and message operations (getsockopt, setsockopt, recvmsg, sendmsg) and address conversions. There is no data exfiltration, credential harvesting, obfuscation, dynamic code execution, cryptocurrency mining, backdoor, network calls to external servers, file system manipulation, process spawning, or dynamic imports. The code is consistent with the legitimate golang.org/x/net package.

internal/socket/sys_unix.go
low

Use of unsafe package and linkname directives

NPS-1B9DE7598C9D

The file uses //go:linkname to access unexported syscall functions (syscall.getsockopt, syscall.setsockopt) and unsafe.Pointer operations. While this is a known pattern in the golang.org/x/net/internal/socket package for performance and compatibility reasons, it bypasses Go's type safety and relies on internal runtime details that may change. However, no malicious payload is present.

internal/socket/sys_unix.go:15
low

Potential unsafe pointer usage on empty slice

NPS-16610EA1A2D5

Both getsockopt and setsockopt pass unsafe.Pointer(&b[0]) without checking that len(b) > 0. If an empty slice is passed, this would cause an index out of range panic. This is a correctness/robustness issue rather than a security vulnerability, but it's an unsafe pattern.

internal/socket/sys_unix.go:25
low

Process Execution

NPS-EA847DA48E3B

The code executes the external command 'go tool cgo -godefs' via os/exec. This is a standard part of the Go toolchain and is gated behind the 'ignore' build tag, so it only runs during explicit code generation, not during normal package import/build. However, spawning subprocesses is a pattern that warrants scrutiny in a malicious context.

ipv4/gen.go:52
low

File System Writes

NPS-AA77ABEDFF76

The code writes generated Go source files (zsys_*.go and iana.go) to the current directory. This is expected behavior for a code generator, but writing files based on network content could allow an attacker controlling the remote registry to inject arbitrary code into generated files.

ipv4/gen.go:66
low

Network Requests

NPS-5343C17CF877

The code fetches XML data from an external IANA URL (https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xml) via http.Get. While this is a legitimate source for protocol constants, it demonstrates external network dependency and could be a vector for supply chain issues if the remote content were compromised or if the URL were altered in a malicious fork.

ipv4/gen.go:78
low

Unsafe pointer usage

NPS-DE4571B96BD5

Uses unsafe.Pointer for type conversion in getICMPFilter and setICMPFilter. This is a common and legitimate pattern in low-level networking code for zero-copy struct conversion, but could theoretically lead to memory safety issues if sizes mismatched.

ipv4/sockopt_posix.go:39
low

cgo type definitions

NPS-639865DA1D84

This file uses cgo to map C struct types from system headers (sys/socket.h, netinet/in.h, netinet/icmp6.h) to Go types for IPv6 socket programming. It is a standard Go x/net style generated definition file guarded by //go:build ignore, meaning it is not compiled as part of the normal build. It contains no executable logic, network calls, file I/O, process spawning, or dynamic code execution.

ipv6/defs_freebsd.go
low

spawning_process

NPS-12D4212CEA5F

genzsys executes an external command via exec.Command("go", "tool", "cgo", "-godefs", defs). The 'go' binary is resolved via PATH, which in a hostile environment could be hijacked; however, this is standard for Go code generation and argument injection is limited to runtime.GOOS-derived filenames.

ipv6/gen.go:45
low

file_system_write

NPS-2ED369380458

The program writes generated files (zsys_*.go, iana.go) to the current working directory using os.WriteFile with fixed names derived from runtime.GOOS/GOARCH and hardcoded strings. Writes are confined to expected generated-file names, so risk is limited.

ipv6/gen.go:57
low

Unsafe pointer arithmetic

NPS-FF50FC765590

The code uses unsafe.Pointer with fixed offsets to access fields in groupReq and groupSourceReq structs. While this is standard practice in Go's syscall/net packages to match OS-level struct layouts, it is a fragile pattern that could lead to memory corruption if offsets are incorrect. However, no malicious intent is present.

ipv6/sys_darwin.go:61
low

platform-specific code

NPS-80C4106A0D8B

Code contains architecture-specific handling for FreeBSD 32-bit compatibility, which is legitimate for socket options. No suspicious behavior detected.

ipv6/sys_ssmreq.go:24
low

unsafe usage

NPS-175DCABF51EA

Use of unsafe.Pointer for struct-to-byte conversion is standard in this Go networking library but could theoretically lead to memory safety issues if struct sizes or layouts change. However, this is not malicious and is guarded by build constraints and platform-specific code.

ipv6/sys_ssmreq.go:30
low

File System Operation

NPS-E3DC90B247A5

LocalPath() creates a temporary file via os.CreateTemp and then removes it to obtain a unique path for Unix domain socket tests. No tampering with files outside the temporary directory occurs.

nettest/nettest.go
low

Process Execution

NPS-B7505D489518

The code executes the external command 'oslevel' on AIX systems to check the OS version for Unix socket support. This is a benign, read-only system query with no user input involved.

nettest/nettest.go:51
low

Environment variable access

NPS-F698F9903B10

The init() function reads the GODEBUG environment variable to enable packet logging. This is a standard Go debugging mechanism and does not harvest credentials or exfiltrate data. Logging is opt-in and writes only to stdout, not to external servers or files.

quic/log.go:15
low

init function execution

NPS-2646D9705E11

The init() function runs at import time as part of Go's standard initialization semantics. It only performs endianness detection and calls probeRoutingStack() to configure local routing table parsing parameters. No external commands, network activity, or file access occur.

route/sys.go:23
low

unsafe pointer usage

NPS-C7F2D882A5FB

unsafe.Pointer is used only to determine native endianness by inspecting the first byte of a uint32. This is a common, benign idiom in the Go standard library and does not permit arbitrary memory access here.

route/sys.go:26
low

syscall usage

NPS-7E32C0AA7E61

syscall.RTM_VERSION is referenced as a constant fallback for the routing message version. No privileged syscall operations or side effects are performed in this file.

route/sys.go:32
low

import-time side effect / global HTTP registration

NPS-E414530CE7D4

An init() function registers fixed handlers on http.DefaultServeMux and panics if /debug/requests is already registered. This executes at import time and takes over global routing, which is an unexpected invasive side effect for a library and can affect any program that imports the package (directly or transitively).

trace/trace.go:174
low

panic causing denial of service

NPS-FBCE204E5856

The init() function panics when /debug/requests is already registered on DefaultServeMux. Merely importing two copies of golang.org/x/net/trace (e.g., through vendoring) will crash the process at startup, creating a trivially reachable DoS if dependency resolution produces duplicates.

trace/trace.go:176
low

sensitive data rendered without sufficient redaction defaults

NPS-07E4815B0012

Trace titles/events include request URL paths and error messages. Sensitive flag defaults to false for many entries (e.g., LazyPrintf always uses sensitive=false), so unless ShowSensitive is explicitly turned off (only via the optional 'show_sensitive=0' query parameter), potentially sensitive request details are rendered to anyone who can reach the debug endpoints.

trace/trace.go:238
low

ChartsReader custom reader

NPS-8D79609ECB44

The Decoder.CharsetReader field allows the caller to supply a function which returns an io.Reader that is used by the parser. This is not suspicious by itself as it is a documented feature of the stdlib encoding/xml package. No malicious use is present in this file.

webdav/internal/xml/xml.go:154
low

no malicious patterns

NPS-C5A020701DBD

The file is a standard implementation of the WebSocket protocol from the Go standard library (golang.org/x/net/websocket). It contains no data exfiltration, credential harvesting, obfuscated code, dynamic code execution, crypto mining, backdoor/reverse shell, install-time execution, suspicious network requests, file system manipulation, process spawning, or dynamic imports with computed input. All imports and API usage are consistent with the stated purpose of implementing RFC 6455.

websocket/websocket.go

Files reviewed

FileVerdictWhat the reviewer saw
http2/h2c/h2c.go medium The code is a deprecated, unmaintained Go standard-library-adjacent h2c implementation with a documented memory buffering risk and GODEBUG-based logging, but contains no malicious exfiltration, backdoor, or credential-harvesting patterns.
http2/h2i/h2i.go medium This is the official Go x/net h2i diagnostic tool; no malicious patterns such as exfiltration, credential harvesting, or backdoors were found, but it intentionally disables TLS verification when the -insecure flag is used.
http3/http3.go medium The code uses unsafe linkname and reflection for internal test integration, which are not inherently malicious but introduce security and stability risks.
internal/quic/cmd/interop/main.go medium This is an official Go QUIC interop test client/server with intentional insecure test settings (InsecureSkipVerify, key logging) and file serving, but no overt malicious exfiltration, backdoor, or code-execution patterns.
internal/socket/iovec_64bit.go medium The code is a standard part of Go's socket library and contains no malicious patterns, though it uses unsafe pointers as intended for low-level I/O operations.
internal/socket/socket.go medium Legitimate Go x/net socket utility code with standard low-level unsafe pointer and syscall usage; no malicious patterns such as exfiltration, credentials theft, obfuscation, or backdoors detected, though unsafe pointer usage warrants caution.
internal/socket/sys_unix.go medium The code appears to be a legitimate part of the golang.org/x/net internal socket package, using unsafe and linkname for low-level socket operations; no malicious patterns were found, though the unsafe practices warrant a low-severity warning.
ipv4/gen.go medium This is a legitimate Go code generator (go:generate) for the golang.org/x/net/ipv4 package, but it makes external network requests and writes generated files, which introduces low-to-medium supply chain risks; it is not overtly malicious.
ipv6/gen.go medium This is a legitimate Go code generator (guarded by //go:build ignore and only run manually via go generate) that fetches IANA ICMPv6 parameters over HTTP and invokes go tool cgo, with the main residual concern being lack of integrity verification on the remote XML source.
trace/trace.go medium The code is the legitimate golang.org/x/net/trace package, but it registers globally-accessible debug HTTP endpoints at import time and relies on a spoofable RemoteAddr for authorization, which can lead to information disclosure of trace data exposed through DefaultServeMux.
bpf/asm.go safe Cleared by Jev triage; no further analysis needed
bpf/constants.go safe Cleared by Jev triage; no further analysis needed
bpf/doc.go safe Cleared by Jev triage; no further analysis needed
bpf/instructions.go safe Cleared by Jev triage; no further analysis needed
bpf/setter.go safe Cleared by Jev triage; no further analysis needed
bpf/vm.go safe No malicious patterns detected
bpf/vm_instructions.go safe No malicious patterns detected; the code is a standard BPF virtual machine instruction implementation from the Go standard library with only in-memory arithmetic, bounds-checked loads, and no network, file system, process, or dynamic code execution behavior.
context/context.go safe Cleared by Jev triage; no further analysis needed
context/ctxhttp/ctxhttp.go safe No malicious patterns detected
dict/dict.go safe No malicious patterns detected; this is the standard Go dictionary protocol client library implementing RFC 2229 with no exfiltration, process spawning, or obfuscation.
dns/dnsmessage/message.go safe Cleared by Jev triage; no further analysis needed
dns/dnsmessage/svcb.go safe Cleared by Jev triage; no further analysis needed
html/atom/atom.go safe Cleared by Jev triage; no further analysis needed
html/atom/gen.go safe This is a standard Go code generator from the Go standard library that produces HTML atom lookup tables; it contains no malicious patterns, network calls, credential access, or dynamic code execution.
html/atom/table.go safe No malicious patterns detected; this is a generated Go source file containing only static HTML atom definitions and lookup tables.
Show 488 more files
FileVerdictWhat the reviewer saw
html/charset/charset.go safe Cleared by Jev triage; no further analysis needed
html/const.go safe Cleared by Jev triage; no further analysis needed
html/doc.go safe Cleared by Jev triage; no further analysis needed
html/doctype.go safe Cleared by Jev triage; no further analysis needed
html/escape.go safe Cleared by Jev triage; no further analysis needed
html/foreign.go safe Cleared by Jev triage; no further analysis needed
html/iter.go safe Cleared by Jev triage; no further analysis needed
html/node.go safe Cleared by Jev triage; no further analysis needed
html/nodetype_string.go safe Auto-generated stringer code for NodeType enum contains only standard String() method and compile-time assertions, with no malicious patterns.
html/parse.go safe No malicious patterns detected; this is the standard Go html package parser with no network, filesystem, or code execution behavior.
html/render.go safe Cleared by Jev triage; no further analysis needed
html/token.go safe No malicious patterns detected; this is a legitimate Go standard library HTML tokenizer with no network, filesystem, process, or obfuscation concerns.
http/httpguts/guts.go safe Cleared by Jev triage; no further analysis needed
http/httpguts/httplex.go safe Cleared by Jev triage; no further analysis needed
http/httpproxy/proxy.go safe No malicious patterns detected; the code is the standard Go httpproxy package for proxy configuration from environment variables.
http2/ascii.go safe Cleared by Jev triage; no further analysis needed
http2/ciphers.go safe Cleared by Jev triage; no further analysis needed
http2/client_conn_pool.go safe No malicious patterns detected; this is the standard Go HTTP/2 client connection pool implementation with no exfiltration, credential harvesting, obfuscation, or unsafe execution behavior.
http2/client_priority_go126.go safe Cleared by Jev triage; no further analysis needed
http2/client_priority_go127.go safe Cleared by Jev triage; no further analysis needed
http2/clientconn.go safe No malicious patterns detected; the file contains only standard, thin wrapper methods for an HTTP/2 client connection with no network exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
http2/config.go safe Cleared by Jev triage; no further analysis needed
http2/config_go125.go safe Cleared by Jev triage; no further analysis needed
http2/config_go126.go safe Cleared by Jev triage; no further analysis needed
http2/databuffer.go safe Cleared by Jev triage; no further analysis needed
http2/errors.go safe Cleared by Jev triage; no further analysis needed
http2/flow.go safe Cleared by Jev triage; no further analysis needed
http2/frame.go safe No malicious patterns detected; this is standard Go HTTP/2 frame parsing code from the golang.org/x/net package with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
http2/gotrack.go safe No malicious patterns detected; the code is a benign debug utility from the Go standard library's http2 package.
http2/hpack/encode.go safe Cleared by Jev triage; no further analysis needed
http2/hpack/gen.go safe This is a legitimate Go code generation tool from the official golang.org/x/net/http2/hpack package that generates static HPACK table definitions; it contains no malicious patterns, network access, credential harvesting, or dynamic code execution.
http2/hpack/hpack.go safe This is a standard implementation of HPACK header compression for HTTP/2 from the Go standard library, with no malicious patterns or security concerns detected.
http2/hpack/huffman.go safe Cleared by Jev triage; no further analysis needed
http2/hpack/static_table.go safe No malicious patterns detected; this is a standard HPACK static table definition for HTTP/2 header compression.
http2/hpack/tables.go safe Cleared by Jev triage; no further analysis needed
http2/http2.go safe The code is a legitimate part of the Go standard library's HTTP/2 implementation (golang.org/x/net/http2) with no malicious patterns; the only environment variable access is standard Go debugging configuration.
http2/pipe.go safe Cleared by Jev triage; no further analysis needed
http2/server.go safe No malicious patterns detected; this is a legitimate copy of the standard Go HTTP/2 server implementation from golang.org/x/net/http2.
http2/server_common.go safe Cleared by Jev triage; no further analysis needed
http2/server_wrap.go safe No malicious patterns detected in the reviewed Go source file; it contains standard HTTP/2 server configuration and compatibility code with no exfiltration, credential harvesting, obfuscation, or process execution.
http2/transport.go safe This is the standard Go x/net/http2 Transport implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution detected.
http2/transport_common.go safe No malicious patterns detected; this is standard Go HTTP/2 transport code from golang.org/x/net/http2 with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
http2/transport_wrap.go safe No malicious patterns detected; the code is a legitimate part of Go's x/net/http2 transport wrapping implementation with no suspicious network, filesystem, process, or obfuscation behavior.
http2/unencrypted.go safe No malicious patterns detected; the code is a utility for retrieving an unencrypted net.Conn from a *tls.Conn with strict type checking.
http2/write.go safe This is a legitimate portion of the Go standard library's HTTP/2 implementation with no malicious patterns; only minor robustness concerns exist.
http2/writesched.go safe Cleared by Jev triage; no further analysis needed
http2/writesched_common.go safe Cleared by Jev triage; no further analysis needed
http2/writesched_priority_rfc7540.go safe Cleared by Jev triage; no further analysis needed
http2/writesched_priority_rfc9218.go safe Cleared by Jev triage; no further analysis needed
http2/writesched_random.go safe Cleared by Jev triage; no further analysis needed
http2/writesched_roundrobin.go safe Cleared by Jev triage; no further analysis needed
icmp/dstunreach.go safe Cleared by Jev triage; no further analysis needed
icmp/echo.go safe Cleared by Jev triage; no further analysis needed
icmp/endpoint.go safe No malicious patterns detected; this is a standard ICMP PacketConn wrapper from the official golang.org/x/net package with only platform-specific read handling and no exfiltration, obfuscation, or system manipulation.
icmp/extension.go safe No malicious patterns detected; the code is standard ICMP extension parsing from the Go standard library ecosystem with no network, file system, process execution, or obfuscation concerns.
icmp/helper_posix.go safe No malicious patterns detected; the code is a standard Go library helper for ICMP socket address conversion with no network exfiltration, credential harvesting, obfuscation, or process spawning.
icmp/interface.go safe No malicious patterns detected
icmp/ipv4.go safe Cleared by Jev triage; no further analysis needed
icmp/ipv6.go safe Cleared by Jev triage; no further analysis needed
icmp/listen_posix.go safe No malicious patterns detected
icmp/listen_stub.go safe Cleared by Jev triage; no further analysis needed
icmp/message.go safe Cleared by Jev triage; no further analysis needed
icmp/messagebody.go safe Cleared by Jev triage; no further analysis needed
icmp/mpls.go safe Cleared by Jev triage; no further analysis needed
icmp/multipart.go safe Cleared by Jev triage; no further analysis needed
icmp/packettoobig.go safe Cleared by Jev triage; no further analysis needed
icmp/paramprob.go safe Cleared by Jev triage; no further analysis needed
icmp/sys_freebsd.go safe This is a standard FreeBSD platform initialization file that only reads the OS release date via syscall.SysctlUint32, with no malicious patterns.
icmp/timeexceeded.go safe Cleared by Jev triage; no further analysis needed
idna/idna.go safe Cleared by Jev triage; no further analysis needed
idna/punycode.go safe Cleared by Jev triage; no further analysis needed
idna/trie.go safe Cleared by Jev triage; no further analysis needed
idna/trieval.go safe Cleared by Jev triage; no further analysis needed
internal/gate/gate.go safe Cleared by Jev triage; no further analysis needed
internal/http3/body.go safe No malicious patterns detected
internal/http3/conn.go safe No malicious patterns detected; the code implements standard HTTP/3 connection stream handling without exfiltration, credential harvesting, or dynamic execution.
internal/http3/doc.go safe Cleared by Jev triage; no further analysis needed
internal/http3/errors.go safe Cleared by Jev triage; no further analysis needed
internal/http3/gzip.go safe Cleared by Jev triage; no further analysis needed
internal/http3/http3.go safe No malicious patterns detected
internal/http3/qpack.go safe This code implements QPACK header compression for HTTP/3 and contains no malicious patterns, data exfiltration, credential harvesting, obfuscation, or other security concerns.
internal/http3/qpack_decode.go safe No malicious patterns detected; the code is a standard QPACK decoder implementation for HTTP/3 with no network, filesystem, process, or dynamic code execution concerns.
internal/http3/qpack_encode.go safe Cleared by Jev triage; no further analysis needed
internal/http3/qpack_static.go safe No malicious patterns detected; the code is a standard QPACK static table definition with safe indexing and lazy map initialization.
internal/http3/quic.go safe Cleared by Jev triage; no further analysis needed
internal/http3/roundtrip.go safe This is a legitimate Go standard library HTTP/3 transport implementation with no malicious patterns detected.
internal/http3/server.go safe No malicious patterns detected; the code is a legitimate HTTP/3 server implementation from the Go standard library with no signs of data exfiltration, credential harvesting, or backdoors.
internal/http3/settings.go safe The code implements standard HTTP/3 SETTINGS frame serialization/deserialization with no malicious patterns; only a minor robustness concern about potential panics on invalid varint values.
internal/http3/stream.go safe No malicious patterns detected; the code is a legitimate HTTP/3 stream wrapper from the Go standard library.
internal/http3/transport.go safe No malicious patterns detected; the code is a standard HTTP/3 transport implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
internal/http3/varint.go safe Cleared by Jev triage; no further analysis needed
internal/httpcommon/ascii.go safe Cleared by Jev triage; no further analysis needed
internal/httpcommon/headermap.go safe Cleared by Jev triage; no further analysis needed
internal/httpcommon/request.go safe No malicious patterns detected; the code is standard HTTP header encoding/decoding from Go's x/net library with no network calls, file access, process execution, obfuscation, or credential harvesting.
internal/httpsfv/httpsfv.go safe Cleared by Jev triage; no further analysis needed
internal/iana/const.go safe Cleared by Jev triage; no further analysis needed
internal/iana/gen.go safe The file is a legitimate Go code generator for IANA constants with expected network fetches and local file writes; no malicious patterns detected.
internal/quic/quicwire/wire.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_bsd.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_linux_32bit.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_linux_64bit.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_solaris_64bit.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_stub.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_unix.go safe Cleared by Jev triage; no further analysis needed
internal/socket/cmsghdr_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
internal/socket/complete_dontwait.go safe No malicious patterns detected
internal/socket/complete_nodontwait.go safe No malicious patterns detected
internal/socket/defs_aix.go safe No malicious patterns detected; the file contains only standard cgo type aliases and constants for socket-related C structs, guarded by a build constraint.
internal/socket/defs_darwin.go safe No malicious patterns detected
internal/socket/defs_dragonfly.go safe No malicious patterns detected
internal/socket/defs_freebsd.go safe No malicious patterns detected
internal/socket/defs_linux.go safe No malicious patterns detected; this is a standard Go cgo type definition file for socket-related C structs with no executable logic or risky behavior.
internal/socket/defs_netbsd.go safe No malicious patterns detected; this is a standard Go cgo type/constant definition file for NetBSD socket structures with no executable logic, network activity, file system access, or dynamic code execution.
internal/socket/defs_openbsd.go safe No malicious patterns detected
internal/socket/defs_solaris.go safe No malicious patterns detected
internal/socket/error_unix.go safe No malicious patterns detected; the code is a standard error-handling helper from the Go standard library's socket package.
internal/socket/error_windows.go safe No malicious patterns detected
internal/socket/iovec_32bit.go safe The code is a standard, safe use of unsafe.Pointer to build iovec structs for network syscalls; no malicious patterns detected.
internal/socket/iovec_solaris_64bit.go safe No malicious patterns detected
internal/socket/iovec_stub.go safe Cleared by Jev triage; no further analysis needed
internal/socket/mmsghdr_stub.go safe Cleared by Jev triage; no further analysis needed
internal/socket/mmsghdr_unix.go safe No malicious patterns detected; this is legitimate low-level socket handling code from the Go standard library ecosystem with no exfiltration, credential harvesting, obfuscation, or network manipulation.
internal/socket/msghdr_bsd.go safe No malicious patterns detected; this is standard Go standard-library-adjacent code for managing socket message headers with legitimate unsafe pointer usage for syscall interop.
internal/socket/msghdr_bsdvar.go safe Cleared by Jev triage; no further analysis needed
internal/socket/msghdr_linux.go safe No malicious patterns detected; this is standard low-level socket msghdr manipulation code from the Go standard library ecosystem using unsafe pointers for legitimate OS syscall structure building.
internal/socket/msghdr_linux_32bit.go safe No malicious patterns detected
internal/socket/msghdr_linux_64bit.go safe No malicious patterns detected; this is standard Go syscall helper code for building msghdr structures with no external I/O, execution, or data harvesting behavior.
internal/socket/msghdr_openbsd.go safe Cleared by Jev triage; no further analysis needed
internal/socket/msghdr_solaris_64bit.go safe This is standard Go socket message header packing code for Solaris amd64 with no malicious patterns.
internal/socket/msghdr_stub.go safe Cleared by Jev triage; no further analysis needed
internal/socket/msghdr_zos_s390x.go safe No malicious patterns detected in the msghdr packing code for z/OS s390x; it only manipulates memory structures for socket operations without network, filesystem, or process execution.
internal/socket/norace.go safe Cleared by Jev triage; no further analysis needed
internal/socket/race.go safe The code is a standard Go race detector instrumentation file with no malicious patterns; it only uses runtime race detector functions on message buffers under the race build tag.
internal/socket/rawconn.go safe No malicious patterns detected; the code is a standard syscall-level socket option wrapper with no exfiltration, obfuscation, or dynamic execution
internal/socket/rawconn_mmsg.go safe The code is a legitimate low-level networking implementation from Go's extended socket library with no malicious patterns.
internal/socket/rawconn_msg.go safe No malicious patterns detected
internal/socket/rawconn_nommsg.go safe Cleared by Jev triage; no further analysis needed
internal/socket/rawconn_nomsg.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_bsd.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_const_unix.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux.go safe No malicious patterns detected
internal/socket/sys_linux_386.go safe This file contains standard Go syscall wrappers for recvmmsg/sendmmsg on Linux 386 and exhibits no malicious patterns.
internal/socket/sys_linux_amd64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_arm.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_arm64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_loong64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_mips.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_mips64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_mips64le.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_mipsle.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_ppc.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_ppc64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_ppc64le.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_riscv64.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_linux_s390x.go safe This file contains standard Go syscall wrappers for recvmmsg/sendmmsg on Linux 386 and exhibits no malicious patterns.
internal/socket/sys_netbsd.go safe No malicious patterns detected
internal/socket/sys_posix.go safe No malicious patterns detected
internal/socket/sys_stub.go safe Cleared by Jev triage; no further analysis needed
internal/socket/sys_windows.go safe No malicious patterns detected
internal/socket/sys_zos_s390x.go safe No malicious patterns detected
internal/socket/zsys_aix_ppc64.go safe No malicious patterns detected; the file contains only platform-specific generated struct definitions and constants for AIX networking, with no executable code, imports, or side effects.
internal/socket/zsys_darwin_amd64.go safe No malicious patterns detected
internal/socket/zsys_darwin_arm64.go safe No malicious patterns detected
internal/socket/zsys_dragonfly_amd64.go safe No malicious patterns detected; the file contains only generated cgo struct definitions and size constants for DragonFly BSD socket operations.
internal/socket/zsys_freebsd_386.go safe No malicious patterns detected
internal/socket/zsys_freebsd_amd64.go safe No malicious patterns detected
internal/socket/zsys_freebsd_arm.go safe No malicious patterns detected
internal/socket/zsys_freebsd_arm64.go safe No malicious patterns detected
internal/socket/zsys_freebsd_riscv64.go safe No malicious patterns detected
internal/socket/zsys_linux_386.go safe This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
internal/socket/zsys_linux_amd64.go safe No malicious patterns detected
internal/socket/zsys_linux_arm.go safe This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
internal/socket/zsys_linux_arm64.go safe No malicious patterns detected
internal/socket/zsys_linux_loong64.go safe No malicious patterns detected
internal/socket/zsys_linux_mips.go safe This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
internal/socket/zsys_linux_mips64.go safe No malicious patterns detected
internal/socket/zsys_linux_mips64le.go safe No malicious patterns detected
internal/socket/zsys_linux_mipsle.go safe This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
internal/socket/zsys_linux_ppc.go safe This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
internal/socket/zsys_linux_ppc64.go safe No malicious patterns detected
internal/socket/zsys_linux_ppc64le.go safe No malicious patterns detected
internal/socket/zsys_linux_riscv64.go safe This is a cgo-generated Linux RISC-V system call type definition file with no executable logic or malicious patterns.
internal/socket/zsys_linux_s390x.go safe No malicious patterns detected
internal/socket/zsys_netbsd_386.go safe This file contains only cgo-generated Go type definitions for socket structures on NetBSD/386 and has no executable code or malicious patterns.
internal/socket/zsys_netbsd_amd64.go safe No malicious patterns detected; this is a generated cgo type definition file for NetBSD socket structures with only type declarations and constants.
internal/socket/zsys_netbsd_arm.go safe This file contains only cgo-generated Go type definitions for socket structures on NetBSD/386 and has no executable code or malicious patterns.
internal/socket/zsys_netbsd_arm64.go safe No malicious patterns detected; this is a generated cgo type definition file for NetBSD socket structures with only type declarations and constants.
internal/socket/zsys_openbsd_386.go safe This is a machine-generated cgo type definition file for OpenBSD 386 socket structures; it contains only struct and constant declarations with no executable code or malicious patterns.
internal/socket/zsys_openbsd_amd64.go safe This file contains only low-level Go struct and constant definitions for OpenBSD amd64 socket syscall bindings, generated by cgo -godefs, with no executable code or malicious patterns.
internal/socket/zsys_openbsd_arm.go safe This is a machine-generated cgo type definition file for OpenBSD 386 socket structures; it contains only struct and constant declarations with no executable code or malicious patterns.
internal/socket/zsys_openbsd_arm64.go safe This file contains only low-level Go struct and constant definitions for OpenBSD amd64 socket syscall bindings, generated by cgo -godefs, with no executable code or malicious patterns.
internal/socket/zsys_openbsd_mips64.go safe This is a cgo-generated Go file containing only platform-specific struct definitions and constants for OpenBSD/mips64 socket handling, with no executable code or malicious patterns.
internal/socket/zsys_openbsd_ppc64.go safe This is a cgo-generated Go file containing only platform-specific struct definitions and constants for OpenBSD/mips64 socket handling, with no executable code or malicious patterns.
internal/socket/zsys_openbsd_riscv64.go safe This is a cgo-generated Go file containing only platform-specific struct definitions and constants for OpenBSD/mips64 socket handling, with no executable code or malicious patterns.
internal/socket/zsys_solaris_amd64.go safe No malicious patterns detected
internal/socket/zsys_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
internal/socks/client.go safe No malicious patterns detected in this standard SOCKS5 client implementation from the Go standard library.
internal/socks/socks.go safe This is the standard Go x/net/internal/socks SOCKS5 client implementation with no malicious patterns, no data exfiltration, no credential harvesting, no obfuscation, and no unauthorized network or filesystem operations.
internal/sockstest/server.go safe This is a legitimate Go standard library testing utility for SOCKS proxy handshakes with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
internal/testcert/testcert.go safe This file contains only hardcoded test certificates and keys with no network, filesystem, process execution, or obfuscated code, intended for testing purposes.
internal/timeseries/timeseries.go safe Cleared by Jev triage; no further analysis needed
ipv4/batch.go safe No malicious patterns detected
ipv4/control.go safe No malicious patterns detected; the code is a standard Go standard-library-derived implementation for IPv4 control messages with no network exfiltration, credential harvesting, obfuscation, or process spawning.
ipv4/control_bsd.go safe No malicious patterns detected
ipv4/control_pktinfo.go safe This is a standard Go network control message implementation for IPv4 packet info with no malicious patterns detected.
ipv4/control_stub.go safe No malicious patterns detected
ipv4/control_unix.go safe This is standard Go standard-library-style code for IPv4 socket control message handling with no malicious patterns, network exfiltration, credential access, or dynamic execution.
ipv4/control_windows.go safe No malicious patterns detected
ipv4/control_zos.go safe No malicious patterns detected; the file is a standard Go stdlib/x-net IPv4 control message implementation using documented socket APIs and unsafe pointer casts for packet info.
ipv4/defs_aix.go safe This is a standard Go cgo definition file from the official Go x/net package with no malicious patterns; it only maps C structs to Go types and contains no executable logic.
ipv4/defs_darwin.go safe This file contains only CGo type definitions and size constants for Darwin IPv4 socket structures with no executable code or malicious patterns.
ipv4/defs_dragonfly.go safe No malicious patterns detected
ipv4/defs_freebsd.go safe No malicious patterns detected; this is a standard Go cgo/godefs type definition file from the Go standard library's ipv4 package with only C struct size constants and type aliases.
ipv4/defs_linux.go safe This is a standard Go cgo/godefs definition file from the official Go x/net repository that only declares C struct bindings for Linux IPv4 socket options, with no executable logic or malicious patterns.
ipv4/defs_netbsd.go safe No malicious patterns detected
ipv4/defs_openbsd.go safe No malicious patterns detected
ipv4/defs_solaris.go safe This file contains only CGo type definitions and size constants for Darwin IPv4 socket structures with no executable code or malicious patterns.
ipv4/dgramopt.go safe No malicious patterns detected in this standard Go networking library file; it only implements multicast and socket option helpers for IPv4 datagram connections.
ipv4/doc.go safe This is a standard Go package documentation file containing only comments and no executable code, with no malicious patterns detected.
ipv4/endpoint.go safe No malicious patterns detected
ipv4/genericopt.go safe No malicious patterns detected; the code is a standard Go networking utility for IPv4 TOS and TTL socket options.
ipv4/header.go safe Cleared by Jev triage; no further analysis needed
ipv4/helper.go safe No malicious patterns detected; the code is from the standard Go net library with only benign helper functions.
ipv4/iana.go safe Cleared by Jev triage; no further analysis needed
ipv4/icmp.go safe Cleared by Jev triage; no further analysis needed
ipv4/icmp_linux.go safe Cleared by Jev triage; no further analysis needed
ipv4/icmp_stub.go safe Cleared by Jev triage; no further analysis needed
ipv4/packet.go safe No malicious patterns detected; this is standard Go network packet handling code from the golang.org/x/net package.
ipv4/payload.go safe No malicious patterns detected
ipv4/payload_cmsg.go safe No malicious patterns detected; the code is a standard Go networking utility from golang.org/x/net for IPv4 payload handling.
ipv4/payload_nocmsg.go safe This file is a standard Go x/net/ipv4 payload handler implementation with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process spawning.
ipv4/sockopt.go safe No malicious patterns detected
ipv4/sockopt_posix.go safe No malicious patterns detected; the file is legitimate Go standard library networking code for IPv4 socket options using standard low-level syscall patterns.
ipv4/sockopt_stub.go safe No malicious patterns detected
ipv4/sys_aix.go safe This is a standard Go networking module file for AIX IPv4 socket options from golang.org/x/net; no malicious patterns detected.
ipv4/sys_asmreq.go safe No malicious patterns detected; this is standard Go networking code for IPv4 multicast socket options from the official golang.org/x/net package.
ipv4/sys_asmreq_stub.go safe No malicious patterns detected; the file contains only stub implementations of multicast socket option functions that return errNotImplemented on unsupported platforms.
ipv4/sys_asmreqn.go safe No malicious patterns detected; the code is standard Go networking code for IPv4 multicast socket options using unsafe pointer casts, with no exfiltration, process spawning, or obfuscation.
ipv4/sys_asmreqn_stub.go safe No malicious patterns detected
ipv4/sys_bpf.go safe No malicious patterns detected; the code is a standard Go networking utility for attaching BPF filters and matches the official golang.org/x/net/ipv4 package.
ipv4/sys_bpf_stub.go safe No malicious patterns detected in the stub implementation file.
ipv4/sys_bsd.go safe No malicious patterns detected; the file contains standard Go network socket option definitions for BSD systems.
ipv4/sys_darwin.go safe No malicious patterns detected; this is standard Go standard library code for IPv4 socket options on Darwin, with expected low-level syscall and unsafe pointer usage.
ipv4/sys_dragonfly.go safe No malicious patterns detected
ipv4/sys_freebsd.go safe No malicious patterns detected; the code is a standard Go network library file for FreeBSD-specific IPv4 socket options.
ipv4/sys_linux.go safe No malicious patterns detected; this is standard Go networking code from golang.org/x/net for IPv4 socket options on Linux.
ipv4/sys_solaris.go safe No malicious patterns detected; the file contains standard Go networking code for IPv4 socket options on Solaris using unsafe pointer arithmetic consistent with its purpose.
ipv4/sys_ssmreq.go safe No malicious patterns detected; the code is legitimate Go standard library network socket option handling.
ipv4/sys_ssmreq_stub.go safe No malicious patterns detected in the stub implementation for non-supported platforms.
ipv4/sys_stub.go safe Cleared by Jev triage; no further analysis needed
ipv4/sys_windows.go safe No malicious patterns detected; this is a standard Go networking library file for Windows IPv4 socket options with no execution, network, or file system activity.
ipv4/sys_zos.go safe This is a legitimate Go standard library submodule (golang.org/x/net/ipv4) for z/OS platform socket options with no malicious patterns detected.
ipv4/zsys_aix_ppc64.go safe No malicious patterns detected; the file contains only standard Go cgo-generated type definitions and constants for IPv4 multicast requests on AIX.
ipv4/zsys_darwin.go safe No malicious patterns detected
ipv4/zsys_dragonfly.go safe No malicious patterns detected
ipv4/zsys_freebsd_386.go safe No malicious patterns detected
ipv4/zsys_freebsd_amd64.go safe No malicious patterns detected
ipv4/zsys_freebsd_arm.go safe No malicious patterns detected
ipv4/zsys_freebsd_arm64.go safe No malicious patterns detected
ipv4/zsys_freebsd_riscv64.go safe No malicious patterns detected
ipv4/zsys_linux_386.go safe This is auto-generated Go cgo type definition code for Linux 386 syscalls with no executable logic or malicious patterns
ipv4/zsys_linux_amd64.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_arm.go safe This is auto-generated Go cgo type definition code for Linux 386 syscalls with no executable logic or malicious patterns
ipv4/zsys_linux_arm64.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_loong64.go safe No malicious patterns detected; this is a generated cgo godefs file containing only type and constant definitions for Linux loong64 syscalls.
ipv4/zsys_linux_mips.go safe This is auto-generated Go cgo type definition code for Linux 386 syscalls with no executable logic or malicious patterns
ipv4/zsys_linux_mips64.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_mips64le.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_mipsle.go safe This is auto-generated Go cgo type definition code for Linux 386 syscalls with no executable logic or malicious patterns
ipv4/zsys_linux_ppc.go safe No malicious patterns detected; the file contains only Go type and constant definitions generated by cgo for Linux ppc system call interoperability.
ipv4/zsys_linux_ppc64.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_ppc64le.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_linux_riscv64.go safe No malicious patterns detected; this is a machine-generated cgo godefs file containing only constant and struct definitions for IPv4 socket options on linux/riscv64.
ipv4/zsys_linux_s390x.go safe This file contains only cgo-generated Go type definitions and constants for Linux IPv4 socket structures, with no executable logic or malicious patterns.
ipv4/zsys_netbsd.go safe No malicious patterns detected; the file contains only a cgo-generated constant and struct definition for IPv4 multicast request on NetBSD with no executable code, network calls, or suspicious behavior.
ipv4/zsys_openbsd.go safe No malicious patterns detected
ipv4/zsys_solaris.go safe No malicious patterns detected
ipv4/zsys_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
ipv6/batch.go safe No malicious patterns detected
ipv6/control.go safe This is a legitimate standard library file from golang.org/x/net/ipv6 implementing control message handling for IPv6 sockets, with no malicious patterns detected.
ipv6/control_rfc2292_unix.go safe No malicious patterns detected; code is standard Go IPv6 socket control message marshaling for Darwin, using unsafe pointer casts on byte slices for struct overlay consistent with the x/net standard library.
ipv6/control_rfc3542_unix.go safe No malicious patterns detected
ipv6/control_stub.go safe No malicious patterns detected
ipv6/control_unix.go safe No malicious patterns detected
ipv6/control_windows.go safe No malicious patterns detected
ipv6/defs_aix.go safe No malicious patterns detected; this is a standard Go cgo definitions file for IPv6 socket structures on AIX.
ipv6/defs_darwin.go safe No malicious patterns detected
ipv6/defs_dragonfly.go safe No malicious patterns detected; this is a standard Go cgo/godefs bindings file for DragonFly BSD IPv6 constants and types, with no executable or network code.
ipv6/defs_freebsd.go safe This is a benign Go cgo type-definition file for IPv6 constants and struct mappings with no malicious behavior.
ipv6/defs_linux.go safe No malicious patterns detected
ipv6/defs_netbsd.go safe No malicious patterns detected; this is a standard Go cgo/godefs bindings file for DragonFly BSD IPv6 constants and types, with no executable or network code.
ipv6/defs_openbsd.go safe No malicious patterns detected; this is a standard Go cgo/godefs bindings file for DragonFly BSD IPv6 constants and types, with no executable or network code.
ipv6/defs_solaris.go safe No malicious patterns detected
ipv6/dgramopt.go safe This is a standard Go standard library networking file for IPv6 datagram socket options with no malicious patterns, external network calls, credential access, or dynamic code execution.
ipv6/doc.go safe Cleared by Jev triage; no further analysis needed
ipv6/endpoint.go safe No malicious patterns detected in the IPv6 endpoint implementation from golang.org/x/net/ipv6.
ipv6/genericopt.go safe Standard Go networking option accessors with no malicious patterns detected
ipv6/header.go safe Cleared by Jev triage; no further analysis needed
ipv6/helper.go safe Cleared by Jev triage; no further analysis needed
ipv6/iana.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_bsd.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_linux.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_solaris.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_stub.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_windows.go safe Cleared by Jev triage; no further analysis needed
ipv6/icmp_zos.go safe Cleared by Jev triage; no further analysis needed
ipv6/payload.go safe No malicious patterns detected
ipv6/payload_cmsg.go safe This file contains standard IPv6 payload read/write operations using the golang.org/x/net package with no malicious patterns detected.
ipv6/payload_nocmsg.go safe No malicious patterns detected; this is a standard Go standard-library style implementation of IPv6 payload ReadFrom/WriteTo with no suspicious behavior.
ipv6/sockopt.go safe No malicious patterns detected
ipv6/sockopt_posix.go safe This file is a standard part of the golang.org/x/net/ipv6 package and contains only legitimate socket option manipulation code with no malicious patterns.
ipv6/sockopt_stub.go safe No malicious patterns detected
ipv6/sys_aix.go safe No malicious patterns detected
ipv6/sys_asmreq.go safe No malicious patterns detected; the code is a standard Go network socket option helper for IPv6 multicast interface configuration using unsafe pointer casting that is bounded by size constants.
ipv6/sys_asmreq_stub.go safe This is a standard Go standard library stub file that returns errNotImplemented on unsupported platforms; no malicious patterns detected.
ipv6/sys_bpf.go safe This is standard Go standard library code for attaching a BPF filter to an IPv6 socket, with no malicious patterns detected.
ipv6/sys_bpf_stub.go safe No malicious patterns detected
ipv6/sys_bsd.go safe This is a legitimate Go standard library IPv6 socket option configuration file for BSD platforms with no malicious patterns detected.
ipv6/sys_darwin.go safe This is a legitimate, unmodified file from the Go standard library (golang.org/x/net/ipv6) for Darwin/BSD IPv6 socket options; no malicious patterns detected.
ipv6/sys_freebsd.go safe No malicious patterns detected; this is standard Go standard-library networking code for IPv6 socket options on FreeBSD.
ipv6/sys_linux.go safe No malicious patterns detected
ipv6/sys_solaris.go safe No malicious patterns detected; this is a standard Go IPv6 socket options implementation using unsafe pointer arithmetic in a manner consistent with the x/net package.
ipv6/sys_ssmreq.go safe The code is part of the legitimate Go x/net package for setting IPv6 socket options; no malicious patterns such as data exfiltration, credential harvesting, code execution, or network backdoors were detected.
ipv6/sys_ssmreq_stub.go safe No malicious patterns detected
ipv6/sys_stub.go safe Cleared by Jev triage; no further analysis needed
ipv6/sys_windows.go safe No malicious patterns detected
ipv6/sys_zos.go safe The file contains standard Go networking code for IPv6 socket options on z/OS, with no malicious patterns, external calls, or suspicious behavior.
ipv6/zsys_aix_ppc64.go safe No malicious patterns detected
ipv6/zsys_darwin.go safe This is a cgo-generated Go source file containing only type and constant definitions for IPv6 socket structures on Darwin (macOS), with no executable code, imports, network activity, or suspicious patterns.
ipv6/zsys_dragonfly.go safe No malicious patterns detected
ipv6/zsys_freebsd_386.go safe No malicious patterns detected
ipv6/zsys_freebsd_amd64.go safe No malicious patterns detected
ipv6/zsys_freebsd_arm.go safe No malicious patterns detected
ipv6/zsys_freebsd_arm64.go safe No malicious patterns detected
ipv6/zsys_freebsd_riscv64.go safe No malicious patterns detected
ipv6/zsys_linux_386.go safe No malicious patterns detected
ipv6/zsys_linux_amd64.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_arm.go safe No malicious patterns detected
ipv6/zsys_linux_arm64.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_loong64.go safe No malicious patterns detected
ipv6/zsys_linux_mips.go safe No malicious patterns detected
ipv6/zsys_linux_mips64.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_mips64le.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_mipsle.go safe No malicious patterns detected
ipv6/zsys_linux_ppc.go safe No malicious patterns detected
ipv6/zsys_linux_ppc64.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_ppc64le.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_linux_riscv64.go safe No malicious patterns detected; this is a cgo-generated Go file containing only constant and struct definitions for IPv6 socket structures on linux/riscv64.
ipv6/zsys_linux_s390x.go safe Generated cgo type definitions for IPv6 socket structures with no executable logic, network calls, or suspicious patterns.
ipv6/zsys_netbsd.go safe No malicious patterns detected in this generated Go type definition file for NetBSD IPv6 syscalls.
ipv6/zsys_openbsd.go safe No malicious patterns detected
ipv6/zsys_solaris.go safe No malicious patterns detected
ipv6/zsys_zos_s390x.go safe Cleared by Jev triage; no further analysis needed
lif/address.go safe The code is from the standard Go library, implements platform-specific network interface address retrieval for Solaris, and contains no malicious patterns such as data exfiltration, credential harvesting, or backdoor installation.
lif/binary.go safe Cleared by Jev triage; no further analysis needed
lif/defs_solaris.go safe No malicious patterns detected
lif/lif.go safe No malicious patterns detected
lif/link.go safe This is a legitimate Go standard library file for Solaris network interface enumeration using ioctl syscalls, with no malicious patterns detected.
lif/sys.go safe No malicious patterns detected
lif/syscall.go safe No malicious patterns detected
lif/zsys_solaris_amd64.go safe No malicious patterns detected
nettest/conntest.go safe No malicious patterns detected; this is a legitimate Go standard library test file for net.Conn implementations with no exfiltration, credential harvesting, obfuscation, or unsafe operations.
nettest/nettest.go safe The code is standard Go network testing utilities from the Go standard library; no malicious patterns or data exfiltration, credential harvesting, backdoors, or obfuscation were found.
nettest/nettest_stub.go safe Cleared by Jev triage; no further analysis needed
nettest/nettest_unix.go safe No malicious patterns detected; the code only probes raw socket support for network testing purposes.
nettest/nettest_windows.go safe The code only probes for raw socket support on Windows and contains no malicious patterns; it is part of the Go standard library's testing utilities.
netutil/listen.go safe Cleared by Jev triage; no further analysis needed
proxy/dial.go safe No malicious patterns detected; the code is a standard Go proxy dialer utility from the golang.org/x/net/proxy package that only uses context and net for connection handling.
proxy/direct.go safe No malicious patterns detected
proxy/per_host.go safe No malicious patterns detected
proxy/proxy.go safe This is the standard golang.org/x/net/proxy package with only legitimate proxy dialing and environment variable reading for proxy configuration, no malicious patterns detected.
proxy/socks5.go safe No malicious patterns detected; the code is a standard SOCKS5 proxy dialer from the Go standard library with no suspicious behavior.
publicsuffix/gen.go safe No malicious patterns detected; the code is a legitimate code generator for the publicsuffix package that fetches the public suffix list and writes table.go and table_test.go, with no exfiltration, credential harvesting, obfuscation, or malicious behavior.
publicsuffix/list.go safe Cleared by Jev triage; no further analysis needed
publicsuffix/table.go safe No malicious patterns detected
quic/ack_delay.go safe Cleared by Jev triage; no further analysis needed
quic/acks.go safe Cleared by Jev triage; no further analysis needed
quic/atomic_bits.go safe Cleared by Jev triage; no further analysis needed
quic/config.go safe Cleared by Jev triage; no further analysis needed
quic/congestion_reno.go safe Cleared by Jev triage; no further analysis needed
quic/conn.go safe No malicious patterns detected; code is standard QUIC connection handling from Go's standard library.
quic/conn_close.go safe No malicious patterns detected; the code is a standard QUIC connection close state machine with no network, filesystem, or process manipulation.
quic/conn_flow.go safe No malicious patterns detected; the code is a legitimate QUIC flow control implementation with no suspicious network, filesystem, credential, or code execution behavior.
quic/conn_id.go safe No malicious patterns detected; the code is a standard QUIC connection ID management implementation from the Go standard library ecosystem, using only crypto/rand and in-memory data structures without any network, file system, process execution, or obfuscation concerns.
quic/conn_loss.go safe Cleared by Jev triage; no further analysis needed
quic/conn_recv.go safe No malicious patterns detected; the file is a legitimate QUIC connection receive handler from the Go standard library's experimental QUIC implementation.
quic/conn_send.go safe No malicious patterns detected; this is legitimate QUIC protocol send-path implementation from the Go standard library's x/net/quic package.
quic/conn_streams.go safe No malicious patterns detected; the code is a standard QUIC stream management implementation from the Go standard library with no external network, credential, or process manipulation.
quic/crypto_stream.go safe No malicious patterns detected
quic/dgram.go safe Cleared by Jev triage; no further analysis needed
quic/doc.go safe Cleared by Jev triage; no further analysis needed
quic/endpoint.go safe No malicious patterns detected; code is a standard QUIC endpoint implementation with no exfiltration, credential harvesting, obfuscation, or other red flags.
quic/errors.go safe Cleared by Jev triage; no further analysis needed
quic/frame_debug.go safe Cleared by Jev triage; no further analysis needed
quic/gate.go safe Cleared by Jev triage; no further analysis needed
quic/idle.go safe No malicious patterns detected
quic/log.go safe The code only implements opt-in GODEBUG-based packet logging to stdout with no network, file system, or credential access concerns.
quic/loss.go safe Cleared by Jev triage; no further analysis needed
quic/math.go safe Cleared by Jev triage; no further analysis needed
quic/pacer.go safe Cleared by Jev triage; no further analysis needed
quic/packet.go safe This is a standard QUIC protocol packet parsing implementation from the Go standard library with no malicious patterns detected.
quic/packet_number.go safe Cleared by Jev triage; no further analysis needed
quic/packet_parser.go safe No malicious patterns detected in the QUIC packet parser; it contains only standard parsing logic with proper bounds checking, no network calls, file access, process execution, or obfuscation.
quic/packet_protection.go safe No malicious patterns detected; this is a standard QUIC packet protection implementation from the Go project with expected cryptographic and network handling code.
quic/packet_writer.go safe No malicious patterns detected
quic/path.go safe No malicious patterns detected
quic/ping.go safe The file contains a single benign ping method for a QUIC connection with no malicious patterns, external calls, or dynamic code execution.
quic/pipe.go safe Cleared by Jev triage; no further analysis needed
quic/qlog.go safe This is a legitimate qlog logging implementation for the Go quic package; it only uses standard logging, hex encoding, and network address formatting with no malicious behavior.
quic/qlog/handler.go safe Cleared by Jev triage; no further analysis needed
quic/qlog/json_writer.go safe Cleared by Jev triage; no further analysis needed
quic/qlog/qlog.go safe The qlog package only writes local qlog trace files with proper path validation; no malicious patterns detected.
quic/queue.go safe Cleared by Jev triage; no further analysis needed
quic/quic.go safe Cleared by Jev triage; no further analysis needed
quic/race_disabled.go safe Cleared by Jev triage; no further analysis needed
quic/race_enabled.go safe No malicious patterns detected; the code only uses Go's runtime race detector synchronization primitives in a build-tagged file.
quic/rangeset.go safe Cleared by Jev triage; no further analysis needed
quic/retry.go safe No malicious patterns detected; this is legitimate QUIC Retry packet implementation from the Go standard library's x/net package.
quic/rtt.go safe Cleared by Jev triage; no further analysis needed
quic/sent_packet.go safe Cleared by Jev triage; no further analysis needed
quic/sent_packet_list.go safe Cleared by Jev triage; no further analysis needed
quic/sent_val.go safe Cleared by Jev triage; no further analysis needed
quic/skip.go safe Cleared by Jev triage; no further analysis needed
quic/stateless_reset.go safe No malicious patterns detected
quic/stream.go safe No malicious patterns detected; this is a legitimate QUIC stream implementation from the Go standard library's internal x/net/quic package.
quic/stream_limits.go safe No malicious patterns detected; the code is a legitimate QUIC stream limit implementation with no network, filesystem, or process manipulation.
quic/tls.go safe No malicious patterns detected; the code is a legitimate QUIC TLS handshake implementation from the Go standard library.
quic/transport_params.go safe No malicious patterns detected; the code is a standard QUIC transport parameter implementation from golang.org/x/net.
quic/udp.go safe Cleared by Jev triage; no further analysis needed
quic/udp_darwin.go safe No malicious patterns detected in this Darwin-specific QUIC UDP socket option handling code.
quic/udp_linux.go safe No malicious patterns detected
quic/udp_msg.go safe No malicious patterns detected; the code is a legitimate QUIC UDP connection implementation using syscall control messages for ECN and packet info.
quic/udp_other.go safe No malicious patterns detected
quic/udp_packetconn.go safe No malicious patterns detected
route/address.go safe No malicious patterns detected
route/binary.go safe Cleared by Jev triage; no further analysis needed
route/defs_darwin.go safe No malicious patterns detected in the CGO constant definitions for Darwin route socket structures.
route/defs_dragonfly.go safe No malicious patterns detected
route/defs_freebsd.go safe No malicious patterns detected; the file only defines FreeBSD routing structures and C size constants with build tag 'ignore' and contains no executable or suspicious code.
route/defs_netbsd.go safe No malicious patterns detected
route/defs_openbsd.go safe No malicious patterns detected
route/interface.go safe Cleared by Jev triage; no further analysis needed
route/interface_announce.go safe Cleared by Jev triage; no further analysis needed
route/interface_classic.go safe No malicious patterns detected
route/interface_freebsd.go safe No malicious patterns detected; this is standard Go standard-library routing code for parsing FreeBSD interface messages with proper bounds checking.
route/interface_multicast.go safe Cleared by Jev triage; no further analysis needed
route/interface_openbsd.go safe No malicious patterns detected; the code is a standard Go standard library routing parser for OpenBSD interface messages with proper bounds checks and no network, file system, or process manipulation.
route/message.go safe Cleared by Jev triage; no further analysis needed
route/route.go safe No malicious patterns detected; the code is a legitimate Go standard library routing package with no network, credential harvesting, or dynamic execution behavior.
route/route_classic.go safe No malicious patterns detected; this is standard Go standard library code for BSD/macOS routing table message marshaling and parsing.
route/route_openbsd.go safe No malicious patterns detected; the code is a standard Go library implementation for marshaling and parsing OpenBSD routing messages.
route/sys.go safe This file is part of the Go standard library's BSD/Darwin route package; it performs only benign endianness detection and routing stack probing with no malicious patterns.
route/sys_darwin.go safe This file is standard Go standard library code for parsing routing messages on Darwin, with no malicious patterns detected.
route/sys_dragonfly.go safe This is legitimate Go standard library routing code for DragonFly BSD with no malicious patterns detected.
route/sys_freebsd.go safe No malicious patterns detected; the file is a standard Go standard library implementation for routing message parsing on FreeBSD.
route/sys_netbsd.go safe No malicious patterns detected; this is standard Go standard library routing code for NetBSD with no network, filesystem, process execution, or obfuscation concerns.
route/sys_openbsd.go safe No malicious patterns detected in this standard Go routing stack implementation for OpenBSD.
route/syscall.go safe This is a legitimate part of the Go standard library's x/net/route package that uses linkname to access the syscall.sysctl function for routing table operations on BSD/Darwin systems; no malicious patterns detected.
route/zsys_darwin.go safe No malicious patterns detected
route/zsys_dragonfly.go safe The file contains only constant size definitions for DragonFly BSD route structures and no malicious patterns.
route/zsys_freebsd_386.go safe This file contains only constant definitions for FreeBSD routing message structure sizes, generated by cgo, with no executable code, imports, network access, file operations, or other malicious patterns.
route/zsys_freebsd_amd64.go safe No malicious patterns detected
route/zsys_freebsd_arm.go safe No malicious patterns detected; the file contains only generated constant definitions for FreeBSD routing message sizes.
route/zsys_freebsd_arm64.go safe No malicious patterns detected
route/zsys_freebsd_riscv64.go safe No malicious patterns detected
route/zsys_netbsd.go safe No malicious patterns detected
route/zsys_openbsd.go safe No malicious patterns detected
trace/events.go safe No malicious patterns detected
trace/histogram.go safe No malicious patterns detected in histogram.go; the code implements histogram statistics within the Go standard library trace package without any exfiltration, credential access, obfuscation, or dynamic execution.
webdav/file.go safe No malicious patterns detected; this is a legitimate Go webdav file system implementation with proper path resolution and no external communications, credential access, or code execution.
webdav/if.go safe Cleared by Jev triage; no further analysis needed
webdav/internal/xml/marshal.go safe Cleared by Jev triage; no further analysis needed
webdav/internal/xml/read.go safe No malicious patterns detected; the code is a standard XML unmarshalling implementation from the Go standard library with no network, filesystem, process, or obfuscation concerns.
webdav/internal/xml/typeinfo.go safe Cleared by Jev triage; no further analysis needed
webdav/internal/xml/xml.go safe This is a copy of the Go standard library encoding/xml parser package with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution.
webdav/litmus_test_server.go safe No malicious patterns detected in this WebDAV litmus test server; the code is a standard Go example that runs locally with no exfiltration, credential harvesting, or backdoor behavior.
webdav/lock.go safe No malicious patterns detected; this is the standard Go x/net/webdav lock implementation.
webdav/prop.go safe No malicious patterns detected; this is the standard Go webdav prop.go file implementing WebDAV property handling for the golang.org/x/net/webdav package.
webdav/webdav.go safe This is the standard Go x/net/webdav package implementation with no malicious patterns detected.
webdav/xml.go safe This is a legitimate WebDAV XML parsing file from the golang.org/x/net/webdav package with no malicious patterns detected.
websocket/client.go safe No malicious patterns detected in the provided Go websocket client code; it is standard library code with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
websocket/dial.go safe No malicious patterns detected; the code implements standard WebSocket dialing logic without any suspicious behavior.
websocket/hybi.go safe No malicious patterns detected; this is a standard Go WebSocket protocol implementation from the Go standard library's x/net/websocket package with no signs of exfiltration, credential harvesting, obfuscation, or backdoor behavior.
websocket/server.go safe No malicious patterns detected
websocket/websocket.go safe This is a legitimate Go WebSocket protocol implementation with no malicious patterns or security concerns.
xsrftoken/xsrf.go safe This is the legitimate golang.org/x/net/xsrftoken package implementing standard HMAC-SHA1 based XSRF token generation and validation with no malicious patterns.

Frequently asked questions

Is golang.org/x/net safe to use?

No confirmed malware was found in golang.org/x/net@v0.59.0, but the review flagged 11 medium, 42 low severity findings for risky patterns worth checking before you rely on it.

Does golang.org/x/net contain malware?

No malware was identified in golang.org/x/net@v0.59.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was golang.org/x/net checked?

Togoder Security downloaded the published Go package and had an AI model read its 513 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan golang.org/x/net together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/net@v0.59.0, cost nothing.

Related security reports