# golang.org/x/text@v0.42.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:51.000Z
- Files reviewed: 254
- Findings: 7 medium, 31 low severity findings
- Report: https://security.togoder.click/go/golang.org/x/text
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package golang.org/x/text@v0.42.0 on Oct 5, 2026. An AI review of 254 source files produced 7 medium, 31 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential out-of-bounds read / incorrect string conversion

Finding ID: `NPS-68AB13D36074`

File: `cases/icu.go:65`

The return value cn is not validated. If an ICU error occurs, cn may be negative or -1, and slicing buf[:cn] would panic or produce incorrect results. Additionally, buf is sized as len(input)*4 which may be insufficient for some case mappings, risking buffer overflow in the C code.

### [medium] Insecure network request (HTTP not HTTPS)

Finding ID: `NPS-F9BF1C9C6FDA`

File: `encoding/japanese/maketables.go`

The maketables.go generator fetches Unicode mapping data over plain HTTP from encoding.spec.whatwg.org (lines using http.Get with http:// URLs). This allows a man-in-the-middle to tamper with the JIS0208/JIS0212 mapping tables that are then baked into generated source, potentially producing corrupted or attacker-influenced encoding tables. While this is a build-time generator (//go:build ignore), it is a genuine supply-chain integrity concern.

### [medium] Suspicious network requests

Finding ID: `NPS-EDA0F876FB99`

File: `encoding/simplifiedchinese/maketables.go:27`

The generator fetches data over plain HTTP from encoding.spec.whatwg.org in printGB18030 and printGBK. While these are legitimate WHATWG specification URLs, using http:// instead of https:// allows network attackers to tamper with the downloaded table data.

### [medium] Insecure network request (HTTP, not HTTPS)

Finding ID: `NPS-FA9B0157B123`

File: `encoding/traditionalchinese/maketables.go:30`

The program fetches a remote file from http://encoding.spec.whatwg.org/index-big5.txt over plain HTTP, which is vulnerable to man-in-the-middle tampering. An attacker could substitute the fetched data, potentially causing generation of incorrect or malicious encoding tables. While this is a code-generation script (not a runtime dependency), the use of HTTP instead of HTTPS is a security weakness.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-66A548433C58`

File: `gen.go:75`

The code modifies files in GOROOT (e.g., api/except.txt, api/next.txt) and copies packages to a destination directory outside the current module (../). This could alter the Go standard library or other repositories if run in an unexpected environment.

### [medium] Use of log.Fatal for error handling

Finding ID: `NPS-547B65C851B6`

File: `internal/gen/gen.go:70`

The code extensively uses log.Fatal which will terminate the program on errors. While not a security vulnerability per se, this pattern can cause unexpected termination if the code is used in a larger application context where graceful error handling is expected.

### [medium] Process execution

Finding ID: `NPS-DE9295AC5A5B`

File: `internal/testtext/codesize.go:37`

The function invokes the Go compiler via exec.Command to build arbitrary source code provided by the caller, which could be abused if untrusted input is passed to CodeSize.

### [low] Memory leak / resource management

Finding ID: `NPS-3EC32396EF8C`

File: `cases/icu.go:34`

The C strings allocated by C.CString (loc and src) are never freed, and the ucasemap_t handle cm is never closed with ucasemap_close, causing memory leaks per invocation.

### [low] CGO and unsafe pointer usage

Finding ID: `NPS-BEACD59B636E`

File: `cases/icu.go:37`

Uses unsafe.Pointer to pass a Go byte slice to C. While not inherently malicious, passing a pointer to a Go-managed slice to C code can lead to memory safety issues if the C code retains the pointer or if the slice is moved by GC.

### [low] init function execution

Finding ID: `NPS-2278809C84B9`

File: `collate/collate.go:48`

The package contains two init() functions that execute at import time: one parses the availableLocales constant and populates the tags slice, and another (go:generate directive) is a comment for code generation. Both are benign and perform static locale parsing with no external interaction, network access, or file system manipulation.

### [low] network data fetch

Finding ID: `NPS-91D8DB743E30`

File: `collate/maketables.go:175`

The generator downloads CLDR data from the web via gen.OpenCLDRCoreZip(), which performs network requests. This is expected for a table generator, but it is a network dependency that could be a supply chain risk if the remote data is compromised.

### [low] unvalidated download / archive extraction

Finding ID: `NPS-691105A08087`

File: `collate/maketables.go:175`

The code downloads a ZIP archive from the network and extracts/parses files from it without cryptographic signature verification. A compromised remote source could deliver malicious CLDR data influencing generated tables.

### [low] write to filesystem

Finding ID: `NPS-8AA1F9EBB3F3`

File: `collate/maketables.go:373`

gen.WriteGoFile("tables.go", *pkg, w.Bytes()) writes generated Go code to the current working directory outside of a clearly contained temp path. This is normal for a build-time generator but writes to an arbitrary path chosen by the caller.

### [low] Network request

Finding ID: `NPS-94E4FE607EA7`

File: `encoding/htmlindex/gen.go`

The program fetches 'encodings.json' from the official WHATWG specification site (https://encoding.spec.whatwg.org). This is the intended purpose of this code generator and is not malicious.

### [low] File system output

Finding ID: `NPS-736C95AE12DD`

File: `encoding/htmlindex/gen.go`

The generator writes a generated Go source file ('tables.go') using gen.WriteGoFile. This is standard behavior for a code generation tool and is confined to the package's own scope.

### [low] Code generation tool

Finding ID: `NPS-1FB2684EF5D5`

File: `encoding/ianaindex/gen.go`

This file is a Go code generator (build tag 'ignore') that parses the IANA character-sets XML registry and generates an iana index table. It does not contain any network requests, environment/credential harvesting, obfuscation, dynamic code execution, backdoors, reverse shells, crypto mining, or shell command execution.

### [low] Build-time code generation from external sources

Finding ID: `NPS-4C8A5621A0A8`

File: `encoding/japanese/maketables.go`

The program downloads external files at generation time and writes them into the package's tables.go. Although the file is excluded from normal compilation via the 'ignore' build tag and is only run manually by maintainers, the generated output becomes part of the published package. Any compromise of the remote source or transport could poison the encoding tables. No signature or hash verification is performed on downloaded content.

### [low] build-time code generation

Finding ID: `NPS-A2DB6311751C`

File: `encoding/korean/maketables.go`

The file contains a //go:build ignore directive and is a standalone generator program (package main). It is designed to be run manually with 'go run maketables.go | gofmt > tables.go' and does not execute at import time.

### [low] network request

Finding ID: `NPS-1F1B89FB4952`

File: `encoding/korean/maketables.go:30`

The file makes an HTTP GET request to encoding.spec.whatwg.org to download the EUC-KR encoding index. This is a legitimate, expected part of the table generation tool and is not used for data exfiltration.

### [low] Code that runs at build time

Finding ID: `NPS-072C4D56598D`

File: `encoding/simplifiedchinese/maketables.go:12`

The file is a build-time code generator with //go:build ignore, meaning it is not compiled into the package and only intended to be run manually via 'go run maketables.go'. However, executing it performs network requests and generates source code.

### [low] Network request at build/generation time

Finding ID: `NPS-F62CA0141F29`

File: `encoding/traditionalchinese/maketables.go:30`

A top-level network fetch is performed when the file is executed with `go run maketables.go`. This is by design for table generation, but it means the build process depends on an external server and any compromise of that server (especially over HTTP) could affect generated output. No data exfiltration or credential harvesting is present, but the external dependency at generation time should be noted.

### [low] Environment variable usage

Finding ID: `NPS-F95CB529BB6F`

File: `gen.go:71`

The code reads the GOROOT environment variable to construct file paths for modification. This is standard for Go tooling but could be manipulated to target unintended directories.

### [low] Spawning processes or shell commands

Finding ID: `NPS-D98C483D54ED`

File: `gen.go:215`

The code uses os/exec to run 'go generate' and 'go test' commands. While this is expected for a code generation tool, it could be abused if the package arguments are controlled by an attacker to execute arbitrary commands.

### [low] File system manipulation

Finding ID: `NPS-0CF47E24CFBB`

File: `internal/gen/code.go:57`

WriteGoFile and WriteVersionedGoFile call os.Create to create/write files at arbitrary paths specified by callers, and call log.Fatalf on error, which can terminate the process. While expected for a code generation utility in the Go standard library's internal packages, this is file system manipulation outside the immediate package scope.

### [low] File system manipulation

Finding ID: `NPS-E7A441976535`

File: `internal/gen/code.go:71`

WriteVersionedGoFile modifies the output filename via a format string (fileToPattern/updateBuildTags) and then writes to it, indirectly affecting which files are created. This depends on external UnicodeVersion and buildTags functions not shown here.

### [low] Reflection-based encoding

Finding ID: `NPS-764895600DA7`

File: `internal/gen/code.go:175`

Uses reflect and gob encoding to serialize values from arbitrary interface{} inputs. gob.Decode is not used here (only Encode), which limits deserialization risks, but the reflection-heavy code path could be problematic if fed untrusted types. This is standard for codegen tooling.

### [low] Panic on unsupported types

Finding ID: `NPS-D6FB33090A4C`

File: `internal/gen/code.go:331`

writeSlice panics for unsupported element types ('gen: slice elem type not supported'), which can cause denial of service if invoked with unexpected inputs. Expected behavior for an internal generator library.

### [low] Network requests to external servers with configurable URLs

Finding ID: `NPS-7353D4E20BCB`

File: `internal/gen/gen.go:38`

The code performs HTTP GET requests to external servers (unicode.org, iana.org) with URLs that are configurable via command-line flags or environment variables. While this appears to be legitimate data fetching for Unicode/CLDR code generation, the flexibility to redirect these requests to arbitrary URLs could be a security concern if used maliciously. The URLs are hardcoded defaults but can be overridden with -url and -iana flags.

### [low] Dynamic file path construction from environment

Finding ID: `NPS-0432C84313D0`

File: `internal/gen/gen.go:52`

The getEnv function reads environment variables to determine Unicode and CLDR versions, which are then used in file path construction when downloading files. An attacker who controls environment variables could potentially influence which files are downloaded and where they are stored, though the impact appears limited to the tool's intended use case.

### [low] File system manipulation outside package scope

Finding ID: `NPS-D3771207F341`

File: `internal/gen/gen.go:192`

The code downloads files from external sources and writes them to the local filesystem. It uses build.Import to locate the golang.org/x/text package and creates/reads/writes files in the DATA directory. While this is expected behavior for a code generation tool, it does modify files outside the immediate package scope. The tool creates directories and writes downloaded content with 0755 permissions.

### [low] init_function

Finding ID: `NPS-804FB4E83590`

File: `internal/number/decimal.go:415`

Package contains an init() function that precomputes a scale table of powers of 10. This is benign, deterministic initialization with no side effects, network access, or external I/O.

### [low] Filesystem write

Finding ID: `NPS-9B534890C783`

File: `internal/testtext/codesize.go:31`

Writes the provided source string to a temporary file and later removes it, but the content is controlled by the caller and could be used to write arbitrary files if the path were manipulated. The path is constructed safely with filepath.Join and a random temp dir, limiting risk.

### [low] init function execution

Finding ID: `NPS-A148DA945567`

File: `secure/bidirule/bidirule.go:190`

The package contains an init() function that precomputes ASCII bidi properties into a package-level array. This runs at import time but performs only local, deterministic computation with no network, filesystem, or process interaction.

### [low] Network/file access as part of build tooling

Finding ID: `NPS-0B9C8D650877`

File: `unicode/norm/maketables.go`

This is a Go code generator (build tag `//go:build ignore`) that downloads Unicode data files from the web via `gen.OpenUCDFile` (golang.org/x/text/internal/gen) and reads/subsequently writes Go source files into the package directory. It is intended as an offline maintainer tool, not runtime code, and does not ship in the compiled package. However, if executed in an untrusted build environment, it performs outbound network requests and writes to the local package scope (tables.go, data_test.go), which is a build-time side effect worth noting.

### [low] Process exit / fatal error on malformed input

Finding ID: `NPS-C673C40B5709`

File: `unicode/norm/maketables.go`

Numerous `log.Fatal`/`log.Fatalf` calls will terminate the process on unexpected input. This is normal for a generator but could be a DoS vector if the code were ever invoked with attacker-controlled Unicode data files.

### [low] Use of os/exec-like generator via go:generate

Finding ID: `NPS-893C714364BB`

File: `unicode/rangetable/gen.go:65`

The generated file includes a //go:generate directive that runs `go run gen.go --versions=...`. This is a common Go idiom, but go:generate directives can be abused to execute arbitrary commands if the file is modified by a compromised dependency.

### [low] Network request during code generation

Finding ID: `NPS-B79EC642DD31`

File: `unicode/rangetable/gen.go:81`

The script uses gen.Open to fetch remote Unicode data from https://www.unicode.org/Public/. While this is a legitimate build-time code generation step protected by a //go:build ignore tag and does not execute at import time, it demonstrates network fetching behavior that could be repurposed in a malicious fork.

### [low] File generation outside package scope

Finding ID: `NPS-2B1C10563FE5`

File: `unicode/rangetable/gen.go:96`

gen.WriteVersionedGoFile writes tables.go into the package directory. This is a standard Go code generation pattern, but any automated modification of source files outside the expected build outputs should be reviewed.

## Files reviewed

- `cases/icu.go` (medium): The code is a legitimate Go binding for ICU case conversions with some resource management and safety issues, but no malicious intent.
- `collate/maketables.go` (medium): This is a standard Go collation table generator that fetches CLDR data from the web at build time; no malicious patterns, credential harvesting, obfuscation, or shell execution were detected.
- `encoding/japanese/maketables.go` (medium): This is a legitimate Go standard-library code generator (build-tagged 'ignore') that downloads JIS mapping data over plain HTTP and emits tables.go; no malicious exfiltration, backdoors, shell execution, or credential harvesting is present, but the unauthenticated HTTP fetch represents a supply-chain integrity risk.
- `encoding/simplifiedchinese/maketables.go` (medium): This is a legitimate Go build-time table generator with no malicious patterns, but it downloads encoding tables over plain HTTP from WHATWG, which is a minor integrity risk for a code-generation tool.
- `encoding/traditionalchinese/maketables.go` (medium): This is a legitimate Go code-generation utility for Traditional Chinese encoding tables that fetches data over plain HTTP from a known WHATWG URL; no malicious exfiltration, credential harvesting, or backdoor behavior was found, but the insecure HTTP fetch is a medium-severity concern.
- `gen.go` (medium): The code is a legitimate Go code generation tool that modifies files in GOROOT and spawns Go commands, with limited risk of abuse if run in a controlled environment.
- `internal/gen/code.go` (medium): This appears to be a legitimate Go code-generation utility from the Go standard library with no data exfiltration, credential harvesting, obfuscation, process spawning, network access, or dynamic code execution; only expected file-writing behavior for code generation is present.
- `internal/gen/gen.go` (medium): This appears to be a legitimate Go code generation utility from the golang.org/x/text repository that fetches Unicode/CLDR data from official sources, with only minor concerns around configurable URLs and filesystem writes that are expected for its purpose.
- `internal/testtext/codesize.go` (medium): The code is a test utility that writes and compiles Go code; while it executes a compiler process and writes to a temp directory, the operations are scoped and not inherently malicious, though caution is needed if used with untrusted input.
- `unicode/norm/maketables.go` (medium): This is a standard Unicode normalization table generator from the official golang.org/x/text module; it contains no malicious patterns, though as build tooling it fetches data over the network and writes generated files.
- `unicode/rangetable/gen.go` (medium): This is a legitimate Go code generation tool from the golang.org/x/text repository that fetches official Unicode data and generates range tables; it poses no direct malicious threat but contains build-time network and file-write behavior worth noting.
- `cases/cases.go` (safe): Cleared by Jev triage; no further analysis needed
- `cases/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `cases/fold.go` (safe): Cleared by Jev triage; no further analysis needed
- `cases/gen.go` (safe): This is a legitimate Unicode case-folding table generator from the Go standard library with no malicious patterns.
- `cases/gen_trieval.go` (safe): Cleared by Jev triage; no further analysis needed
- `cases/info.go` (safe): Cleared by Jev triage; no further analysis needed
- `cases/map.go` (safe): No malicious patterns detected; the file contains standard Unicode case-mapping logic from golang.org/x/text with no network, filesystem, process, or dynamic execution behavior.
- `cases/trieval.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/gotext/common.go` (safe): No malicious patterns detected; the code is a standard Go package loader for the gotext command-line tool with no data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `cmd/gotext/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/gotext/examples/extract/catalog.go` (safe): No malicious patterns detected; the code is a generated localization catalog using standard golang.org/x/text packages without network, filesystem, environment, or process manipulation.
- `cmd/gotext/examples/extract/main.go` (safe): No malicious patterns detected
- `cmd/gotext/examples/extract_http/catalog_gen.go` (safe): Code is a standard Go-generated i18n catalog with no malicious patterns detected
- `cmd/gotext/examples/extract_http/main.go` (safe): No malicious patterns detected
- `cmd/gotext/examples/extract_http/pkg/pkg.go` (safe): No malicious patterns detected
- `cmd/gotext/examples/rewrite/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/gotext/examples/rewrite/printer.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/gotext/extract.go` (safe): No malicious patterns detected
- `cmd/gotext/generate.go` (safe): No malicious patterns detected
- `cmd/gotext/main.go` (safe): No malicious patterns detected; this is a standard Go CLI tool for managing translations with no exfiltration, credential harvesting, dynamic code execution, or backdoor behavior.
- `cmd/gotext/rewrite.go` (safe): No malicious patterns detected; the file is a standard command implementation for a source code rewriting tool from the official golang.org/x/text module.
- `cmd/gotext/update.go` (safe): No malicious patterns detected
- `collate/build/builder.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/build/colelem.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/build/contract.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/build/order.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/build/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/build/trie.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/collate.go` (safe): No malicious patterns detected; the code is a standard Unicode collation package with benign import-time initialization.
- `collate/index.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/option.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/sort.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/tools/colcmp/col.go` (safe): The Go file contains standard collation comparison utilities from the Go standard library with no malicious patterns, no network/file/process operations, and no install-time or dynamic code execution concerns.
- `collate/tools/colcmp/colcmp.go` (safe): No malicious patterns detected
- `collate/tools/colcmp/darwin.go` (safe): No malicious patterns detected; the code is a legitimate Go collator implementation using cgo to interface with macOS CoreFoundation APIs.
- `collate/tools/colcmp/gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `collate/tools/colcmp/icu.go` (safe): No malicious patterns detected; this is a standard ICU collation wrapper from the Go standard library's collate tool, using CGO for Unicode collation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `currency/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `currency/currency.go` (safe): Cleared by Jev triage; no further analysis needed
- `currency/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `currency/gen.go` (safe): This is a legitimate Go code generator from the official golang.org/x/text repository that processes CLDR data to generate currency tables, with no malicious patterns detected.
- `currency/gen_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `currency/query.go` (safe): Cleared by Jev triage; no further analysis needed
- `date/gen.go` (safe): This is a legitimate Go code generation tool from the golang.org/x/text package that processes CLDR data; no malicious patterns detected.
- `doc.go` (safe): No malicious patterns detected in the package documentation file.
- `encoding/charmap/charmap.go` (safe): No malicious patterns detected
- `encoding/charmap/maketables.go` (safe): This is a legitimate code generator from the golang.org/x/text package that downloads character encoding tables from trusted WHATWG/ICU sources to generate Go source code; no malicious patterns detected.
- `encoding/encoding.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/htmlindex/gen.go` (safe): This is a benign Go code generator (build-ignored via //go:build ignore) that downloads WHATWG encoding data and produces a Go lookup table; no malicious patterns were found.
- `encoding/htmlindex/htmlindex.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/htmlindex/map.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/htmlindex/tables.go` (safe): No malicious patterns detected
- `encoding/ianaindex/ascii.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/ianaindex/gen.go` (safe): The file is a legitimate Go code generator for IANA character-set tables with no malicious patterns detected.
- `encoding/ianaindex/ianaindex.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/ianaindex/tables.go` (safe): No malicious patterns detected; the file is a generated data table of IANA character encoding identifiers, aliases, and MIB mappings with no executable logic, network access, filesystem manipulation, or process spawning.
- `encoding/internal/enctest/enctest.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/internal/identifier/gen.go` (safe): This is a legitimate Go code generator from the standard library's golang.org/x/text repository that parses IANA charset registry XML and generates Go source; no malicious patterns detected.
- `encoding/internal/identifier/identifier.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/internal/identifier/mib.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/internal/internal.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/japanese/all.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/japanese/eucjp.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/japanese/iso2022jp.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/japanese/shiftjis.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/korean/euckr.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/korean/maketables.go` (safe): The code is a legitimate Go code generator for Korean EUC-KR encoding tables with no malicious patterns detected.
- `encoding/simplifiedchinese/all.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/simplifiedchinese/gbk.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/simplifiedchinese/hzgb2312.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/traditionalchinese/big5.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/unicode/override.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/unicode/unicode.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/unicode/utf32/utf32.go` (safe): Cleared by Jev triage; no further analysis needed
- `feature/plural/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `feature/plural/gen.go` (safe): No malicious patterns detected; this is a legitimate Go code generator for CLDR plural rules with no network, credential, or execution abuse.
- `feature/plural/gen_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `feature/plural/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `feature/plural/plural.go` (safe): Cleared by Jev triage; no further analysis needed
- `feature/plural/tables.go` (safe): No malicious patterns detected in the generated CLDR plural rules data tables.
- `internal/catmsg/catmsg.go` (safe): No malicious patterns detected; the code is a legitimate Go text message catalog implementation with no network, filesystem, process, or obfuscation concerns.
- `internal/catmsg/codec.go` (safe): No malicious patterns detected; this is a standard Go text message encoding/decoding library with no network, filesystem, process execution, or credential access.
- `internal/catmsg/varint.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cldrtree/cldrtree.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cldrtree/generate.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cldrtree/option.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cldrtree/testdata/test1/output.go` (safe): No malicious patterns detected; this is a generated CLDR data file containing only static lookup tables and constants.
- `internal/cldrtree/testdata/test2/output.go` (safe): No malicious patterns detected; this is a standard generated Go CLDR data table file with only static data and no network, filesystem, process, or dynamic execution behavior.
- `internal/cldrtree/tree.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cldrtree/type.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/collelem.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/colltab.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/contract.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/iter.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/numeric.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/trie.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/colltab/weighter.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/gen.go` (safe): This is a standard Go code generator for Unicode IDNA tables from the golang.org/x/text repository; no malicious patterns were detected.
- `internal/export/idna/gen_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/gen_trieval.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/idna.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/punycode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/trie.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/idna/trieval.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/export/unicode/doc.go` (safe): No malicious patterns detected
- `internal/export/unicode/gen.go` (safe): This is an official Go standard library code generator with no malicious patterns; it only reads Unicode data files and generates Go source code.
- `internal/format/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/format/parser.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/gen/bitfield/bitfield.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/internal.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/compact.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/compact/compact.go` (safe): This is a standard Go internal package from golang.org/x/text that implements compact language tag representation with no malicious patterns, network calls, process execution, or credential harvesting.
- `internal/language/compact/gen.go` (safe): Legitimate Go code generator for CLDR language tag tables with no malicious patterns detected.
- `internal/language/compact/gen_index.go` (safe): This is a standard Go code generation utility from the golang.org/x/text package that builds compact language tag tables; no malicious patterns, network activity, credential access, or suspicious code execution were found.
- `internal/language/compact/gen_parents.go` (safe): This is a legitimate Go code generation tool that reads CLDR data and writes a parents lookup table; no malicious patterns were detected.
- `internal/language/compact/language.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/compact/parents.go` (safe): No malicious patterns detected
- `internal/language/compact/tables.go` (safe): The file is a generated Go table of language tag indices and compact core info constants, containing no executable logic, network calls, credential access, or other malicious patterns.
- `internal/language/compact/tags.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/compose.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/coverage.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/gen.go` (safe): No malicious patterns detected; the file is a standard Go code generator for language tag tables with no external network, credential, or command execution behavior.
- `internal/language/gen_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/language.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/lookup.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/match.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/parse.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/language/tags.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/match.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/decimal.go` (safe): This is legitimate Go standard library code for decimal number conversion and rounding with no malicious patterns detected.
- `internal/number/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/gen.go` (safe): No malicious patterns detected; this is a standard Go code generator for CLDR number formatting tables.
- `internal/number/gen_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/number.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/pattern.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/number/roundingmode_string.go` (safe): No malicious patterns detected
- `internal/number/tables.go` (safe): No malicious patterns detected; this is a generated CLDR data table file from golang.org/x/text with only static numerical data and no executable logic.
- `internal/stringset/set.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/tag/tag.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testtext/flag.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testtext/gc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testtext/gccgo.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testtext/text.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/triegen/compact.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/triegen/print.go` (safe): No malicious patterns detected; this is standard Go code generation logic for a trie data structure with no network, filesystem, or process execution activity.
- `internal/triegen/triegen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/ucd/ucd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/utf8internal/utf8internal.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/coverage.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/display/dict.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/display/display.go` (safe): No malicious patterns detected
- `language/display/lookup.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/display/maketables.go` (safe): This is a legitimate Go code generator for CLDR display name tables with no malicious patterns detected.
- `language/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/gen.go` (safe): No malicious patterns detected; the file is a standard Go code generator for language tag tables from CLDR data with no exfiltration, credential harvesting, obfuscation, or suspicious execution behavior.
- `language/language.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/match.go` (safe): This is a legitimate Go language matching implementation from golang.org/x/text with no malicious patterns detected.
- `language/parse.go` (safe): Cleared by Jev triage; no further analysis needed
- `language/tables.go` (safe): No malicious patterns detected; the file contains only generated CLDR language data tables and constants from golang.org/x/text.
- `language/tags.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/catalog.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/catalog/catalog.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/catalog/dict.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/pipeline/extract.go` (safe): No malicious patterns detected; this is a standard Go source extraction tool for i18n message extraction without any exfiltration, credential harvesting, or dynamic code execution.
- `message/pipeline/generate.go` (safe): No malicious patterns detected; the code is a legitimate Go code generator for i18n message catalogs with no network, credential access, or dynamic execution.
- `message/pipeline/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/pipeline/pipeline.go` (safe): No malicious patterns detected; the code is a legitimate Go text translation pipeline tool with no network, credential harvesting, obfuscation, or process execution behavior.
- `message/pipeline/rewrite.go` (safe): No malicious patterns detected; this is a legitimate Go source-rewriting tool from the golang.org/x/text repository that performs static AST transformations and file writes only to explicitly targeted Go source files.
- `message/pipeline/testdata/ssa/catalog_gen.go` (safe): No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior.
- `message/pipeline/testdata/ssa/ssa.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/pipeline/testdata/test1/test1.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/pipeline/testdata/test60555/catalog_gen.go` (safe): No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior.
- `message/pipeline/testdata/test60555/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/pipeline/testdata/test60555/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `message/print.go` (safe): Cleared by Jev triage; no further analysis needed
- `number/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `number/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `number/number.go` (safe): Cleared by Jev triage; no further analysis needed
- `number/option.go` (safe): Cleared by Jev triage; no further analysis needed
- `runes/cond.go` (safe): Cleared by Jev triage; no further analysis needed
- `runes/runes.go` (safe): Cleared by Jev triage; no further analysis needed
- `search/index.go` (safe): Cleared by Jev triage; no further analysis needed
- `search/pattern.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
