Summary
Togoder Security scanned the Go package golang.org/x/text@v0.42.0 on Oct 5, 2026. An AI review of 254 source files produced 7 medium, 31 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 38
Potential out-of-bounds read / incorrect string conversion
NPS-68AB13D36074
The return value cn is not validated. If an ICU error occurs, cn may be negative or -1, and slicing buf[:cn] would panic or produce incorrect results. Additionally, buf is sized as len(input)*4 which may be insufficient for some case mappings, risking buffer overflow in the C code.
Insecure network request (HTTP not HTTPS)
NPS-F9BF1C9C6FDA
The maketables.go generator fetches Unicode mapping data over plain HTTP from encoding.spec.whatwg.org (lines using http.Get with http:// URLs). This allows a man-in-the-middle to tamper with the JIS0208/JIS0212 mapping tables that are then baked into generated source, potentially producing corrupted or attacker-influenced encoding tables. While this is a build-time generator (//go:build ignore), it is a genuine supply-chain integrity concern.
Suspicious network requests
NPS-EDA0F876FB99
The generator fetches data over plain HTTP from encoding.spec.whatwg.org in printGB18030 and printGBK. While these are legitimate WHATWG specification URLs, using http:// instead of https:// allows network attackers to tamper with the downloaded table data.
Insecure network request (HTTP, not HTTPS)
NPS-FA9B0157B123
The program fetches a remote file from http://encoding.spec.whatwg.org/index-big5.txt over plain HTTP, which is vulnerable to man-in-the-middle tampering. An attacker could substitute the fetched data, potentially causing generation of incorrect or malicious encoding tables. While this is a code-generation script (not a runtime dependency), the use of HTTP instead of HTTPS is a security weakness.
File system manipulation outside package scope
NPS-66A548433C58
The code modifies files in GOROOT (e.g., api/except.txt, api/next.txt) and copies packages to a destination directory outside the current module (../). This could alter the Go standard library or other repositories if run in an unexpected environment.
Use of log.Fatal for error handling
NPS-547B65C851B6
The code extensively uses log.Fatal which will terminate the program on errors. While not a security vulnerability per se, this pattern can cause unexpected termination if the code is used in a larger application context where graceful error handling is expected.
Process execution
NPS-DE9295AC5A5B
The function invokes the Go compiler via exec.Command to build arbitrary source code provided by the caller, which could be abused if untrusted input is passed to CodeSize.
Memory leak / resource management
NPS-3EC32396EF8C
The C strings allocated by C.CString (loc and src) are never freed, and the ucasemap_t handle cm is never closed with ucasemap_close, causing memory leaks per invocation.
CGO and unsafe pointer usage
NPS-BEACD59B636E
Uses unsafe.Pointer to pass a Go byte slice to C. While not inherently malicious, passing a pointer to a Go-managed slice to C code can lead to memory safety issues if the C code retains the pointer or if the slice is moved by GC.
init function execution
NPS-2278809C84B9
The package contains two init() functions that execute at import time: one parses the availableLocales constant and populates the tags slice, and another (go:generate directive) is a comment for code generation. Both are benign and perform static locale parsing with no external interaction, network access, or file system manipulation.
network data fetch
NPS-91D8DB743E30
The generator downloads CLDR data from the web via gen.OpenCLDRCoreZip(), which performs network requests. This is expected for a table generator, but it is a network dependency that could be a supply chain risk if the remote data is compromised.
unvalidated download / archive extraction
NPS-691105A08087
The code downloads a ZIP archive from the network and extracts/parses files from it without cryptographic signature verification. A compromised remote source could deliver malicious CLDR data influencing generated tables.
write to filesystem
NPS-8AA1F9EBB3F3
gen.WriteGoFile("tables.go", *pkg, w.Bytes()) writes generated Go code to the current working directory outside of a clearly contained temp path. This is normal for a build-time generator but writes to an arbitrary path chosen by the caller.
Network request
NPS-94E4FE607EA7
The program fetches 'encodings.json' from the official WHATWG specification site (https://encoding.spec.whatwg.org). This is the intended purpose of this code generator and is not malicious.
File system output
NPS-736C95AE12DD
The generator writes a generated Go source file ('tables.go') using gen.WriteGoFile. This is standard behavior for a code generation tool and is confined to the package's own scope.
Code generation tool
NPS-1FB2684EF5D5
This file is a Go code generator (build tag 'ignore') that parses the IANA character-sets XML registry and generates an iana index table. It does not contain any network requests, environment/credential harvesting, obfuscation, dynamic code execution, backdoors, reverse shells, crypto mining, or shell command execution.
Build-time code generation from external sources
NPS-4C8A5621A0A8
The program downloads external files at generation time and writes them into the package's tables.go. Although the file is excluded from normal compilation via the 'ignore' build tag and is only run manually by maintainers, the generated output becomes part of the published package. Any compromise of the remote source or transport could poison the encoding tables. No signature or hash verification is performed on downloaded content.
build-time code generation
NPS-A2DB6311751C
The file contains a //go:build ignore directive and is a standalone generator program (package main). It is designed to be run manually with 'go run maketables.go | gofmt > tables.go' and does not execute at import time.
network request
NPS-1F1B89FB4952
The file makes an HTTP GET request to encoding.spec.whatwg.org to download the EUC-KR encoding index. This is a legitimate, expected part of the table generation tool and is not used for data exfiltration.
Code that runs at build time
NPS-072C4D56598D
The file is a build-time code generator with //go:build ignore, meaning it is not compiled into the package and only intended to be run manually via 'go run maketables.go'. However, executing it performs network requests and generates source code.
Network request at build/generation time
NPS-F62CA0141F29
A top-level network fetch is performed when the file is executed with go run maketables.go. This is by design for table generation, but it means the build process depends on an external server and any compromise of that server (especially over HTTP) could affect generated output. No data exfiltration or credential harvesting is present, but the external dependency at generation time should be noted.
Environment variable usage
NPS-F95CB529BB6F
The code reads the GOROOT environment variable to construct file paths for modification. This is standard for Go tooling but could be manipulated to target unintended directories.
Spawning processes or shell commands
NPS-D98C483D54ED
The code uses os/exec to run 'go generate' and 'go test' commands. While this is expected for a code generation tool, it could be abused if the package arguments are controlled by an attacker to execute arbitrary commands.
File system manipulation
NPS-0CF47E24CFBB
WriteGoFile and WriteVersionedGoFile call os.Create to create/write files at arbitrary paths specified by callers, and call log.Fatalf on error, which can terminate the process. While expected for a code generation utility in the Go standard library's internal packages, this is file system manipulation outside the immediate package scope.
File system manipulation
NPS-E7A441976535
WriteVersionedGoFile modifies the output filename via a format string (fileToPattern/updateBuildTags) and then writes to it, indirectly affecting which files are created. This depends on external UnicodeVersion and buildTags functions not shown here.
Reflection-based encoding
NPS-764895600DA7
Uses reflect and gob encoding to serialize values from arbitrary interface{} inputs. gob.Decode is not used here (only Encode), which limits deserialization risks, but the reflection-heavy code path could be problematic if fed untrusted types. This is standard for codegen tooling.
Panic on unsupported types
NPS-D6FB33090A4C
writeSlice panics for unsupported element types ('gen: slice elem type not supported'), which can cause denial of service if invoked with unexpected inputs. Expected behavior for an internal generator library.
Network requests to external servers with configurable URLs
NPS-7353D4E20BCB
The code performs HTTP GET requests to external servers (unicode.org, iana.org) with URLs that are configurable via command-line flags or environment variables. While this appears to be legitimate data fetching for Unicode/CLDR code generation, the flexibility to redirect these requests to arbitrary URLs could be a security concern if used maliciously. The URLs are hardcoded defaults but can be overridden with -url and -iana flags.
Dynamic file path construction from environment
NPS-0432C84313D0
The getEnv function reads environment variables to determine Unicode and CLDR versions, which are then used in file path construction when downloading files. An attacker who controls environment variables could potentially influence which files are downloaded and where they are stored, though the impact appears limited to the tool's intended use case.
File system manipulation outside package scope
NPS-D3771207F341
The code downloads files from external sources and writes them to the local filesystem. It uses build.Import to locate the golang.org/x/text package and creates/reads/writes files in the DATA directory. While this is expected behavior for a code generation tool, it does modify files outside the immediate package scope. The tool creates directories and writes downloaded content with 0755 permissions.
init_function
NPS-804FB4E83590
Package contains an init() function that precomputes a scale table of powers of 10. This is benign, deterministic initialization with no side effects, network access, or external I/O.
Filesystem write
NPS-9B534890C783
Writes the provided source string to a temporary file and later removes it, but the content is controlled by the caller and could be used to write arbitrary files if the path were manipulated. The path is constructed safely with filepath.Join and a random temp dir, limiting risk.
init function execution
NPS-A148DA945567
The package contains an init() function that precomputes ASCII bidi properties into a package-level array. This runs at import time but performs only local, deterministic computation with no network, filesystem, or process interaction.
Network/file access as part of build tooling
NPS-0B9C8D650877
This is a Go code generator (build tag //go:build ignore) that downloads Unicode data files from the web via gen.OpenUCDFile (golang.org/x/text/internal/gen) and reads/subsequently writes Go source files into the package directory. It is intended as an offline maintainer tool, not runtime code, and does not ship in the compiled package. However, if executed in an untrusted build environment, it performs outbound network requests and writes to the local package scope (tables.go, data_test.go), which is a build-time side effect worth noting.
Process exit / fatal error on malformed input
NPS-C673C40B5709
Numerous log.Fatal/log.Fatalf calls will terminate the process on unexpected input. This is normal for a generator but could be a DoS vector if the code were ever invoked with attacker-controlled Unicode data files.
Use of os/exec-like generator via go:generate
NPS-893C714364BB
The generated file includes a //go:generate directive that runs go run gen.go --versions=.... This is a common Go idiom, but go:generate directives can be abused to execute arbitrary commands if the file is modified by a compromised dependency.
Network request during code generation
NPS-B79EC642DD31
The script uses gen.Open to fetch remote Unicode data from https://www.unicode.org/Public/. While this is a legitimate build-time code generation step protected by a //go:build ignore tag and does not execute at import time, it demonstrates network fetching behavior that could be repurposed in a malicious fork.
File generation outside package scope
NPS-2B1C10563FE5
gen.WriteVersionedGoFile writes tables.go into the package directory. This is a standard Go code generation pattern, but any automated modification of source files outside the expected build outputs should be reviewed.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cases/icu.go | medium | The code is a legitimate Go binding for ICU case conversions with some resource management and safety issues, but no malicious intent. |
| collate/maketables.go | medium | This is a standard Go collation table generator that fetches CLDR data from the web at build time; no malicious patterns, credential harvesting, obfuscation, or shell execution were detected. |
| encoding/japanese/maketables.go | medium | This is a legitimate Go standard-library code generator (build-tagged 'ignore') that downloads JIS mapping data over plain HTTP and emits tables.go; no malicious exfiltration, backdoors, shell execution, or credential harvesting is present, but the unauthenticated HTTP fetch represents a supply-chain integrity risk. |
| encoding/simplifiedchinese/maketables.go | medium | This is a legitimate Go build-time table generator with no malicious patterns, but it downloads encoding tables over plain HTTP from WHATWG, which is a minor integrity risk for a code-generation tool. |
| encoding/traditionalchinese/maketables.go | medium | This is a legitimate Go code-generation utility for Traditional Chinese encoding tables that fetches data over plain HTTP from a known WHATWG URL; no malicious exfiltration, credential harvesting, or backdoor behavior was found, but the insecure HTTP fetch is a medium-severity concern. |
| gen.go | medium | The code is a legitimate Go code generation tool that modifies files in GOROOT and spawns Go commands, with limited risk of abuse if run in a controlled environment. |
| internal/gen/code.go | medium | This appears to be a legitimate Go code-generation utility from the Go standard library with no data exfiltration, credential harvesting, obfuscation, process spawning, network access, or dynamic code execution; only expected file-writing behavior for code generation is present. |
| internal/gen/gen.go | medium | This appears to be a legitimate Go code generation utility from the golang.org/x/text repository that fetches Unicode/CLDR data from official sources, with only minor concerns around configurable URLs and filesystem writes that are expected for its purpose. |
| internal/testtext/codesize.go | medium | The code is a test utility that writes and compiles Go code; while it executes a compiler process and writes to a temp directory, the operations are scoped and not inherently malicious, though caution is needed if used with untrusted input. |
| unicode/norm/maketables.go | medium | This is a standard Unicode normalization table generator from the official golang.org/x/text module; it contains no malicious patterns, though as build tooling it fetches data over the network and writes generated files. |
| unicode/rangetable/gen.go | medium | This is a legitimate Go code generation tool from the golang.org/x/text repository that fetches official Unicode data and generates range tables; it poses no direct malicious threat but contains build-time network and file-write behavior worth noting. |
| cases/cases.go | safe | Cleared by Jev triage; no further analysis needed |
| cases/context.go | safe | Cleared by Jev triage; no further analysis needed |
| cases/fold.go | safe | Cleared by Jev triage; no further analysis needed |
| cases/gen.go | safe | This is a legitimate Unicode case-folding table generator from the Go standard library with no malicious patterns. |
| cases/gen_trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| cases/info.go | safe | Cleared by Jev triage; no further analysis needed |
| cases/map.go | safe | No malicious patterns detected; the file contains standard Unicode case-mapping logic from golang.org/x/text with no network, filesystem, process, or dynamic execution behavior. |
| cases/trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/gotext/common.go | safe | No malicious patterns detected; the code is a standard Go package loader for the gotext command-line tool with no data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| cmd/gotext/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/gotext/examples/extract/catalog.go | safe | No malicious patterns detected; the code is a generated localization catalog using standard golang.org/x/text packages without network, filesystem, environment, or process manipulation. |
| cmd/gotext/examples/extract/main.go | safe | No malicious patterns detected |
| cmd/gotext/examples/extract_http/catalog_gen.go | safe | Code is a standard Go-generated i18n catalog with no malicious patterns detected |
| cmd/gotext/examples/extract_http/main.go | safe | No malicious patterns detected |
Show 229 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| cmd/gotext/examples/extract_http/pkg/pkg.go | safe | No malicious patterns detected |
| cmd/gotext/examples/rewrite/main.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/gotext/examples/rewrite/printer.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/gotext/extract.go | safe | No malicious patterns detected |
| cmd/gotext/generate.go | safe | No malicious patterns detected |
| cmd/gotext/main.go | safe | No malicious patterns detected; this is a standard Go CLI tool for managing translations with no exfiltration, credential harvesting, dynamic code execution, or backdoor behavior. |
| cmd/gotext/rewrite.go | safe | No malicious patterns detected; the file is a standard command implementation for a source code rewriting tool from the official golang.org/x/text module. |
| cmd/gotext/update.go | safe | No malicious patterns detected |
| collate/build/builder.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/build/colelem.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/build/contract.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/build/order.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/build/table.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/build/trie.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/collate.go | safe | No malicious patterns detected; the code is a standard Unicode collation package with benign import-time initialization. |
| collate/index.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/option.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/sort.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/tools/colcmp/col.go | safe | The Go file contains standard collation comparison utilities from the Go standard library with no malicious patterns, no network/file/process operations, and no install-time or dynamic code execution concerns. |
| collate/tools/colcmp/colcmp.go | safe | No malicious patterns detected |
| collate/tools/colcmp/darwin.go | safe | No malicious patterns detected; the code is a legitimate Go collator implementation using cgo to interface with macOS CoreFoundation APIs. |
| collate/tools/colcmp/gen.go | safe | Cleared by Jev triage; no further analysis needed |
| collate/tools/colcmp/icu.go | safe | No malicious patterns detected; this is a standard ICU collation wrapper from the Go standard library's collate tool, using CGO for Unicode collation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| currency/common.go | safe | Cleared by Jev triage; no further analysis needed |
| currency/currency.go | safe | Cleared by Jev triage; no further analysis needed |
| currency/format.go | safe | Cleared by Jev triage; no further analysis needed |
| currency/gen.go | safe | This is a legitimate Go code generator from the official golang.org/x/text repository that processes CLDR data to generate currency tables, with no malicious patterns detected. |
| currency/gen_common.go | safe | Cleared by Jev triage; no further analysis needed |
| currency/query.go | safe | Cleared by Jev triage; no further analysis needed |
| date/gen.go | safe | This is a legitimate Go code generation tool from the golang.org/x/text package that processes CLDR data; no malicious patterns detected. |
| doc.go | safe | No malicious patterns detected in the package documentation file. |
| encoding/charmap/charmap.go | safe | No malicious patterns detected |
| encoding/charmap/maketables.go | safe | This is a legitimate code generator from the golang.org/x/text package that downloads character encoding tables from trusted WHATWG/ICU sources to generate Go source code; no malicious patterns detected. |
| encoding/encoding.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/htmlindex/gen.go | safe | This is a benign Go code generator (build-ignored via //go:build ignore) that downloads WHATWG encoding data and produces a Go lookup table; no malicious patterns were found. |
| encoding/htmlindex/htmlindex.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/htmlindex/map.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/htmlindex/tables.go | safe | No malicious patterns detected |
| encoding/ianaindex/ascii.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/ianaindex/gen.go | safe | The file is a legitimate Go code generator for IANA character-set tables with no malicious patterns detected. |
| encoding/ianaindex/ianaindex.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/ianaindex/tables.go | safe | No malicious patterns detected; the file is a generated data table of IANA character encoding identifiers, aliases, and MIB mappings with no executable logic, network access, filesystem manipulation, or process spawning. |
| encoding/internal/enctest/enctest.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/internal/identifier/gen.go | safe | This is a legitimate Go code generator from the standard library's golang.org/x/text repository that parses IANA charset registry XML and generates Go source; no malicious patterns detected. |
| encoding/internal/identifier/identifier.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/internal/identifier/mib.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/japanese/all.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/japanese/eucjp.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/japanese/iso2022jp.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/japanese/shiftjis.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/korean/euckr.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/korean/maketables.go | safe | The code is a legitimate Go code generator for Korean EUC-KR encoding tables with no malicious patterns detected. |
| encoding/simplifiedchinese/all.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/simplifiedchinese/gbk.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/simplifiedchinese/hzgb2312.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/traditionalchinese/big5.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/unicode/override.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/unicode/unicode.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/unicode/utf32/utf32.go | safe | Cleared by Jev triage; no further analysis needed |
| feature/plural/common.go | safe | Cleared by Jev triage; no further analysis needed |
| feature/plural/gen.go | safe | No malicious patterns detected; this is a legitimate Go code generator for CLDR plural rules with no network, credential, or execution abuse. |
| feature/plural/gen_common.go | safe | Cleared by Jev triage; no further analysis needed |
| feature/plural/message.go | safe | Cleared by Jev triage; no further analysis needed |
| feature/plural/plural.go | safe | Cleared by Jev triage; no further analysis needed |
| feature/plural/tables.go | safe | No malicious patterns detected in the generated CLDR plural rules data tables. |
| internal/catmsg/catmsg.go | safe | No malicious patterns detected; the code is a legitimate Go text message catalog implementation with no network, filesystem, process, or obfuscation concerns. |
| internal/catmsg/codec.go | safe | No malicious patterns detected; this is a standard Go text message encoding/decoding library with no network, filesystem, process execution, or credential access. |
| internal/catmsg/varint.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cldrtree/cldrtree.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cldrtree/generate.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cldrtree/option.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cldrtree/testdata/test1/output.go | safe | No malicious patterns detected; this is a generated CLDR data file containing only static lookup tables and constants. |
| internal/cldrtree/testdata/test2/output.go | safe | No malicious patterns detected; this is a standard generated Go CLDR data table file with only static data and no network, filesystem, process, or dynamic execution behavior. |
| internal/cldrtree/tree.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cldrtree/type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/collelem.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/colltab.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/contract.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/iter.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/numeric.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/table.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/trie.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/colltab/weighter.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/gen.go | safe | This is a standard Go code generator for Unicode IDNA tables from the golang.org/x/text repository; no malicious patterns were detected. |
| internal/export/idna/gen_common.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/gen_trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/idna.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/punycode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/trie.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/idna/trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/export/unicode/doc.go | safe | No malicious patterns detected |
| internal/export/unicode/gen.go | safe | This is an official Go standard library code generator with no malicious patterns; it only reads Unicode data files and generates Go source code. |
| internal/format/format.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/format/parser.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/gen/bitfield/bitfield.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/common.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/compact.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/compact/compact.go | safe | This is a standard Go internal package from golang.org/x/text that implements compact language tag representation with no malicious patterns, network calls, process execution, or credential harvesting. |
| internal/language/compact/gen.go | safe | Legitimate Go code generator for CLDR language tag tables with no malicious patterns detected. |
| internal/language/compact/gen_index.go | safe | This is a standard Go code generation utility from the golang.org/x/text package that builds compact language tag tables; no malicious patterns, network activity, credential access, or suspicious code execution were found. |
| internal/language/compact/gen_parents.go | safe | This is a legitimate Go code generation tool that reads CLDR data and writes a parents lookup table; no malicious patterns were detected. |
| internal/language/compact/language.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/compact/parents.go | safe | No malicious patterns detected |
| internal/language/compact/tables.go | safe | The file is a generated Go table of language tag indices and compact core info constants, containing no executable logic, network calls, credential access, or other malicious patterns. |
| internal/language/compact/tags.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/compose.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/coverage.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/gen.go | safe | No malicious patterns detected; the file is a standard Go code generator for language tag tables with no external network, credential, or command execution behavior. |
| internal/language/gen_common.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/language.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/lookup.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/match.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/parse.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/language/tags.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/match.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/common.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/decimal.go | safe | This is legitimate Go standard library code for decimal number conversion and rounding with no malicious patterns detected. |
| internal/number/format.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/gen.go | safe | No malicious patterns detected; this is a standard Go code generator for CLDR number formatting tables. |
| internal/number/gen_common.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/number.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/pattern.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/number/roundingmode_string.go | safe | No malicious patterns detected |
| internal/number/tables.go | safe | No malicious patterns detected; this is a generated CLDR data table file from golang.org/x/text with only static numerical data and no executable logic. |
| internal/stringset/set.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/tag/tag.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testtext/flag.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testtext/gc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testtext/gccgo.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testtext/text.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/triegen/compact.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/triegen/print.go | safe | No malicious patterns detected; this is standard Go code generation logic for a trie data structure with no network, filesystem, or process execution activity. |
| internal/triegen/triegen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/ucd/ucd.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/utf8internal/utf8internal.go | safe | Cleared by Jev triage; no further analysis needed |
| language/coverage.go | safe | Cleared by Jev triage; no further analysis needed |
| language/display/dict.go | safe | Cleared by Jev triage; no further analysis needed |
| language/display/display.go | safe | No malicious patterns detected |
| language/display/lookup.go | safe | Cleared by Jev triage; no further analysis needed |
| language/display/maketables.go | safe | This is a legitimate Go code generator for CLDR display name tables with no malicious patterns detected. |
| language/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| language/gen.go | safe | No malicious patterns detected; the file is a standard Go code generator for language tag tables from CLDR data with no exfiltration, credential harvesting, obfuscation, or suspicious execution behavior. |
| language/language.go | safe | Cleared by Jev triage; no further analysis needed |
| language/match.go | safe | This is a legitimate Go language matching implementation from golang.org/x/text with no malicious patterns detected. |
| language/parse.go | safe | Cleared by Jev triage; no further analysis needed |
| language/tables.go | safe | No malicious patterns detected; the file contains only generated CLDR language data tables and constants from golang.org/x/text. |
| language/tags.go | safe | Cleared by Jev triage; no further analysis needed |
| message/catalog.go | safe | Cleared by Jev triage; no further analysis needed |
| message/catalog/catalog.go | safe | Cleared by Jev triage; no further analysis needed |
| message/catalog/dict.go | safe | Cleared by Jev triage; no further analysis needed |
| message/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| message/format.go | safe | Cleared by Jev triage; no further analysis needed |
| message/message.go | safe | Cleared by Jev triage; no further analysis needed |
| message/pipeline/extract.go | safe | No malicious patterns detected; this is a standard Go source extraction tool for i18n message extraction without any exfiltration, credential harvesting, or dynamic code execution. |
| message/pipeline/generate.go | safe | No malicious patterns detected; the code is a legitimate Go code generator for i18n message catalogs with no network, credential access, or dynamic execution. |
| message/pipeline/message.go | safe | Cleared by Jev triage; no further analysis needed |
| message/pipeline/pipeline.go | safe | No malicious patterns detected; the code is a legitimate Go text translation pipeline tool with no network, credential harvesting, obfuscation, or process execution behavior. |
| message/pipeline/rewrite.go | safe | No malicious patterns detected; this is a legitimate Go source-rewriting tool from the golang.org/x/text repository that performs static AST transformations and file writes only to explicitly targeted Go source files. |
| message/pipeline/testdata/ssa/catalog_gen.go | safe | No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior. |
| message/pipeline/testdata/ssa/ssa.go | safe | Cleared by Jev triage; no further analysis needed |
| message/pipeline/testdata/test1/test1.go | safe | Cleared by Jev triage; no further analysis needed |
| message/pipeline/testdata/test60555/catalog_gen.go | safe | No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior. |
| message/pipeline/testdata/test60555/main.go | safe | Cleared by Jev triage; no further analysis needed |
| message/pipeline/testdata/test60555/message.go | safe | Cleared by Jev triage; no further analysis needed |
| message/print.go | safe | Cleared by Jev triage; no further analysis needed |
| number/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| number/format.go | safe | Cleared by Jev triage; no further analysis needed |
| number/number.go | safe | Cleared by Jev triage; no further analysis needed |
| number/option.go | safe | Cleared by Jev triage; no further analysis needed |
| runes/cond.go | safe | Cleared by Jev triage; no further analysis needed |
| runes/runes.go | safe | Cleared by Jev triage; no further analysis needed |
| search/index.go | safe | Cleared by Jev triage; no further analysis needed |
| search/pattern.go | safe | Cleared by Jev triage; no further analysis needed |
| search/search.go | safe | This is a legitimate Go text search package from golang.org/x/text with no malicious patterns, network activity, or suspicious behavior. |
| secure/bidirule/bidirule.go | safe | The file implements RFC 5893 Bidi Rule validation with only local Unicode processing; no malicious patterns detected. |
| secure/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/class.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/context.go | safe | No malicious patterns detected; the code implements PRECIS contextual rules with table-driven logic and an init function that only configures local bitmasks. |
| secure/precis/doc.go | safe | No malicious patterns detected |
| secure/precis/gen.go | safe | No malicious patterns detected; this is a standard Go code generator for Unicode tables with build tag 'ignore' and no runtime execution. |
| secure/precis/gen_trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/nickname.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/options.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/profile.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/profiles.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/transformer.go | safe | Cleared by Jev triage; no further analysis needed |
| secure/precis/trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| transform/transform.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/bidi.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/bracket.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/core.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/gen.go | safe | This is a legitimate Go code generator from the official golang.org/x/text repository that generates Unicode bidirectional text tables and contains no malicious patterns. |
| unicode/bidi/gen_ranges.go | safe | No malicious patterns detected; the file is a standard Go code generator for Unicode bidi ranges with no network, credential, or execution risks. |
| unicode/bidi/gen_trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/prop.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/bidi/trieval.go | safe | No malicious patterns detected in the Go source file; it contains only standard Unicode bidirectional class definitions and constants. |
| unicode/cldr/base.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/cldr/cldr.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/cldr/collate.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/cldr/decode.go | safe | No malicious patterns detected |
| unicode/cldr/makexml.go | safe | No malicious patterns detected; this is a standard Go code generation tool from the official Go source tree that reads CLDR DTD zip data and writes Go XML type definitions. |
| unicode/cldr/resolve.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/cldr/slice.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/cldr/xml.go | safe | This is a generated Go struct definition file for parsing CLDR XML data, containing no executable logic, network calls, or malicious patterns. |
| unicode/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/composition.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/forminfo.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/input.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/iter.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/normalize.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/readwriter.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/transform.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/trie.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/norm/triegen.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/rangetable/merge.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/rangetable/rangetable.go | safe | Cleared by Jev triage; no further analysis needed |
| unicode/runenames/gen.go | safe | This is a benign Go code generation tool from the official golang.org/x/text repository that processes Unicode character data to generate lookup tables, with no malicious patterns detected. |
| unicode/runenames/runenames.go | safe | Cleared by Jev triage; no further analysis needed |
| width/gen.go | safe | No malicious patterns detected |
| width/gen_common.go | safe | This is a standard Go code generator file from the official golang.org/x/text repository with no malicious patterns; it only reads Unicode data files for width table generation. |
| width/gen_trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| width/kind_string.go | safe | This is a standard Go stringer-generated file containing only constant name and index tables with no network, filesystem, process, or dynamic code execution activity. |
| width/tables15.0.0.go | safe | No malicious patterns detected; the file is generated Unicode width table data with only static lookup functions. |
| width/tables17.0.0.go | safe | No malicious patterns detected; this is a standard generated Unicode width lookup table with no network, filesystem, process, or dynamic code execution behavior. |
| width/transform.go | safe | Cleared by Jev triage; no further analysis needed |
| width/trieval.go | safe | Cleared by Jev triage; no further analysis needed |
| width/width.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is golang.org/x/text safe to use?
No confirmed malware was found in golang.org/x/text@v0.42.0, but the review flagged 7 medium, 31 low severity findings for risky patterns worth checking before you rely on it.
Does golang.org/x/text contain malware?
No malware was identified in golang.org/x/text@v0.42.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was golang.org/x/text checked?
Togoder Security downloaded the published Go package and had an AI model read its 254 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan golang.org/x/text together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/text@v0.42.0, cost nothing.