Togoder security

Go package security report

golang.org/x/text@v0.42.0 security report

Risky patterns found that deserve a look.

Needs review Version v0.42.0 Files reviewed 254 Size 9.7 MB Scanned

Summary

Togoder Security scanned the Go package golang.org/x/text@v0.42.0 on Oct 5, 2026. An AI review of 254 source files produced 7 medium, 31 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
7
medium
31
low

Findings 38

medium

Potential out-of-bounds read / incorrect string conversion

NPS-68AB13D36074

The return value cn is not validated. If an ICU error occurs, cn may be negative or -1, and slicing buf[:cn] would panic or produce incorrect results. Additionally, buf is sized as len(input)*4 which may be insufficient for some case mappings, risking buffer overflow in the C code.

cases/icu.go:65
medium

Insecure network request (HTTP not HTTPS)

NPS-F9BF1C9C6FDA

The maketables.go generator fetches Unicode mapping data over plain HTTP from encoding.spec.whatwg.org (lines using http.Get with http:// URLs). This allows a man-in-the-middle to tamper with the JIS0208/JIS0212 mapping tables that are then baked into generated source, potentially producing corrupted or attacker-influenced encoding tables. While this is a build-time generator (//go:build ignore), it is a genuine supply-chain integrity concern.

encoding/japanese/maketables.go
medium

Suspicious network requests

NPS-EDA0F876FB99

The generator fetches data over plain HTTP from encoding.spec.whatwg.org in printGB18030 and printGBK. While these are legitimate WHATWG specification URLs, using http:// instead of https:// allows network attackers to tamper with the downloaded table data.

encoding/simplifiedchinese/maketables.go:27
medium

Insecure network request (HTTP, not HTTPS)

NPS-FA9B0157B123

The program fetches a remote file from http://encoding.spec.whatwg.org/index-big5.txt over plain HTTP, which is vulnerable to man-in-the-middle tampering. An attacker could substitute the fetched data, potentially causing generation of incorrect or malicious encoding tables. While this is a code-generation script (not a runtime dependency), the use of HTTP instead of HTTPS is a security weakness.

encoding/traditionalchinese/maketables.go:30
medium

File system manipulation outside package scope

NPS-66A548433C58

The code modifies files in GOROOT (e.g., api/except.txt, api/next.txt) and copies packages to a destination directory outside the current module (../). This could alter the Go standard library or other repositories if run in an unexpected environment.

gen.go:75
medium

Use of log.Fatal for error handling

NPS-547B65C851B6

The code extensively uses log.Fatal which will terminate the program on errors. While not a security vulnerability per se, this pattern can cause unexpected termination if the code is used in a larger application context where graceful error handling is expected.

internal/gen/gen.go:70
medium

Process execution

NPS-DE9295AC5A5B

The function invokes the Go compiler via exec.Command to build arbitrary source code provided by the caller, which could be abused if untrusted input is passed to CodeSize.

internal/testtext/codesize.go:37
low

Memory leak / resource management

NPS-3EC32396EF8C

The C strings allocated by C.CString (loc and src) are never freed, and the ucasemap_t handle cm is never closed with ucasemap_close, causing memory leaks per invocation.

cases/icu.go:34
low

CGO and unsafe pointer usage

NPS-BEACD59B636E

Uses unsafe.Pointer to pass a Go byte slice to C. While not inherently malicious, passing a pointer to a Go-managed slice to C code can lead to memory safety issues if the C code retains the pointer or if the slice is moved by GC.

cases/icu.go:37
low

init function execution

NPS-2278809C84B9

The package contains two init() functions that execute at import time: one parses the availableLocales constant and populates the tags slice, and another (go:generate directive) is a comment for code generation. Both are benign and perform static locale parsing with no external interaction, network access, or file system manipulation.

collate/collate.go:48
low

network data fetch

NPS-91D8DB743E30

The generator downloads CLDR data from the web via gen.OpenCLDRCoreZip(), which performs network requests. This is expected for a table generator, but it is a network dependency that could be a supply chain risk if the remote data is compromised.

collate/maketables.go:175
low

unvalidated download / archive extraction

NPS-691105A08087

The code downloads a ZIP archive from the network and extracts/parses files from it without cryptographic signature verification. A compromised remote source could deliver malicious CLDR data influencing generated tables.

collate/maketables.go:175
low

write to filesystem

NPS-8AA1F9EBB3F3

gen.WriteGoFile("tables.go", *pkg, w.Bytes()) writes generated Go code to the current working directory outside of a clearly contained temp path. This is normal for a build-time generator but writes to an arbitrary path chosen by the caller.

collate/maketables.go:373
low

Network request

NPS-94E4FE607EA7

The program fetches 'encodings.json' from the official WHATWG specification site (https://encoding.spec.whatwg.org). This is the intended purpose of this code generator and is not malicious.

encoding/htmlindex/gen.go
low

File system output

NPS-736C95AE12DD

The generator writes a generated Go source file ('tables.go') using gen.WriteGoFile. This is standard behavior for a code generation tool and is confined to the package's own scope.

encoding/htmlindex/gen.go
low

Code generation tool

NPS-1FB2684EF5D5

This file is a Go code generator (build tag 'ignore') that parses the IANA character-sets XML registry and generates an iana index table. It does not contain any network requests, environment/credential harvesting, obfuscation, dynamic code execution, backdoors, reverse shells, crypto mining, or shell command execution.

encoding/ianaindex/gen.go
low

Build-time code generation from external sources

NPS-4C8A5621A0A8

The program downloads external files at generation time and writes them into the package's tables.go. Although the file is excluded from normal compilation via the 'ignore' build tag and is only run manually by maintainers, the generated output becomes part of the published package. Any compromise of the remote source or transport could poison the encoding tables. No signature or hash verification is performed on downloaded content.

encoding/japanese/maketables.go
low

build-time code generation

NPS-A2DB6311751C

The file contains a //go:build ignore directive and is a standalone generator program (package main). It is designed to be run manually with 'go run maketables.go | gofmt > tables.go' and does not execute at import time.

encoding/korean/maketables.go
low

network request

NPS-1F1B89FB4952

The file makes an HTTP GET request to encoding.spec.whatwg.org to download the EUC-KR encoding index. This is a legitimate, expected part of the table generation tool and is not used for data exfiltration.

encoding/korean/maketables.go:30
low

Code that runs at build time

NPS-072C4D56598D

The file is a build-time code generator with //go:build ignore, meaning it is not compiled into the package and only intended to be run manually via 'go run maketables.go'. However, executing it performs network requests and generates source code.

encoding/simplifiedchinese/maketables.go:12
low

Network request at build/generation time

NPS-F62CA0141F29

A top-level network fetch is performed when the file is executed with go run maketables.go. This is by design for table generation, but it means the build process depends on an external server and any compromise of that server (especially over HTTP) could affect generated output. No data exfiltration or credential harvesting is present, but the external dependency at generation time should be noted.

encoding/traditionalchinese/maketables.go:30
low

Environment variable usage

NPS-F95CB529BB6F

The code reads the GOROOT environment variable to construct file paths for modification. This is standard for Go tooling but could be manipulated to target unintended directories.

gen.go:71
low

Spawning processes or shell commands

NPS-D98C483D54ED

The code uses os/exec to run 'go generate' and 'go test' commands. While this is expected for a code generation tool, it could be abused if the package arguments are controlled by an attacker to execute arbitrary commands.

gen.go:215
low

File system manipulation

NPS-0CF47E24CFBB

WriteGoFile and WriteVersionedGoFile call os.Create to create/write files at arbitrary paths specified by callers, and call log.Fatalf on error, which can terminate the process. While expected for a code generation utility in the Go standard library's internal packages, this is file system manipulation outside the immediate package scope.

internal/gen/code.go:57
low

File system manipulation

NPS-E7A441976535

WriteVersionedGoFile modifies the output filename via a format string (fileToPattern/updateBuildTags) and then writes to it, indirectly affecting which files are created. This depends on external UnicodeVersion and buildTags functions not shown here.

internal/gen/code.go:71
low

Reflection-based encoding

NPS-764895600DA7

Uses reflect and gob encoding to serialize values from arbitrary interface{} inputs. gob.Decode is not used here (only Encode), which limits deserialization risks, but the reflection-heavy code path could be problematic if fed untrusted types. This is standard for codegen tooling.

internal/gen/code.go:175
low

Panic on unsupported types

NPS-D6FB33090A4C

writeSlice panics for unsupported element types ('gen: slice elem type not supported'), which can cause denial of service if invoked with unexpected inputs. Expected behavior for an internal generator library.

internal/gen/code.go:331
low

Network requests to external servers with configurable URLs

NPS-7353D4E20BCB

The code performs HTTP GET requests to external servers (unicode.org, iana.org) with URLs that are configurable via command-line flags or environment variables. While this appears to be legitimate data fetching for Unicode/CLDR code generation, the flexibility to redirect these requests to arbitrary URLs could be a security concern if used maliciously. The URLs are hardcoded defaults but can be overridden with -url and -iana flags.

internal/gen/gen.go:38
low

Dynamic file path construction from environment

NPS-0432C84313D0

The getEnv function reads environment variables to determine Unicode and CLDR versions, which are then used in file path construction when downloading files. An attacker who controls environment variables could potentially influence which files are downloaded and where they are stored, though the impact appears limited to the tool's intended use case.

internal/gen/gen.go:52
low

File system manipulation outside package scope

NPS-D3771207F341

The code downloads files from external sources and writes them to the local filesystem. It uses build.Import to locate the golang.org/x/text package and creates/reads/writes files in the DATA directory. While this is expected behavior for a code generation tool, it does modify files outside the immediate package scope. The tool creates directories and writes downloaded content with 0755 permissions.

internal/gen/gen.go:192
low

init_function

NPS-804FB4E83590

Package contains an init() function that precomputes a scale table of powers of 10. This is benign, deterministic initialization with no side effects, network access, or external I/O.

internal/number/decimal.go:415
low

Filesystem write

NPS-9B534890C783

Writes the provided source string to a temporary file and later removes it, but the content is controlled by the caller and could be used to write arbitrary files if the path were manipulated. The path is constructed safely with filepath.Join and a random temp dir, limiting risk.

internal/testtext/codesize.go:31
low

init function execution

NPS-A148DA945567

The package contains an init() function that precomputes ASCII bidi properties into a package-level array. This runs at import time but performs only local, deterministic computation with no network, filesystem, or process interaction.

secure/bidirule/bidirule.go:190
low

Network/file access as part of build tooling

NPS-0B9C8D650877

This is a Go code generator (build tag //go:build ignore) that downloads Unicode data files from the web via gen.OpenUCDFile (golang.org/x/text/internal/gen) and reads/subsequently writes Go source files into the package directory. It is intended as an offline maintainer tool, not runtime code, and does not ship in the compiled package. However, if executed in an untrusted build environment, it performs outbound network requests and writes to the local package scope (tables.go, data_test.go), which is a build-time side effect worth noting.

unicode/norm/maketables.go
low

Process exit / fatal error on malformed input

NPS-C673C40B5709

Numerous log.Fatal/log.Fatalf calls will terminate the process on unexpected input. This is normal for a generator but could be a DoS vector if the code were ever invoked with attacker-controlled Unicode data files.

unicode/norm/maketables.go
low

Use of os/exec-like generator via go:generate

NPS-893C714364BB

The generated file includes a //go:generate directive that runs go run gen.go --versions=.... This is a common Go idiom, but go:generate directives can be abused to execute arbitrary commands if the file is modified by a compromised dependency.

unicode/rangetable/gen.go:65
low

Network request during code generation

NPS-B79EC642DD31

The script uses gen.Open to fetch remote Unicode data from https://www.unicode.org/Public/. While this is a legitimate build-time code generation step protected by a //go:build ignore tag and does not execute at import time, it demonstrates network fetching behavior that could be repurposed in a malicious fork.

unicode/rangetable/gen.go:81
low

File generation outside package scope

NPS-2B1C10563FE5

gen.WriteVersionedGoFile writes tables.go into the package directory. This is a standard Go code generation pattern, but any automated modification of source files outside the expected build outputs should be reviewed.

unicode/rangetable/gen.go:96

Files reviewed

FileVerdictWhat the reviewer saw
cases/icu.go medium The code is a legitimate Go binding for ICU case conversions with some resource management and safety issues, but no malicious intent.
collate/maketables.go medium This is a standard Go collation table generator that fetches CLDR data from the web at build time; no malicious patterns, credential harvesting, obfuscation, or shell execution were detected.
encoding/japanese/maketables.go medium This is a legitimate Go standard-library code generator (build-tagged 'ignore') that downloads JIS mapping data over plain HTTP and emits tables.go; no malicious exfiltration, backdoors, shell execution, or credential harvesting is present, but the unauthenticated HTTP fetch represents a supply-chain integrity risk.
encoding/simplifiedchinese/maketables.go medium This is a legitimate Go build-time table generator with no malicious patterns, but it downloads encoding tables over plain HTTP from WHATWG, which is a minor integrity risk for a code-generation tool.
encoding/traditionalchinese/maketables.go medium This is a legitimate Go code-generation utility for Traditional Chinese encoding tables that fetches data over plain HTTP from a known WHATWG URL; no malicious exfiltration, credential harvesting, or backdoor behavior was found, but the insecure HTTP fetch is a medium-severity concern.
gen.go medium The code is a legitimate Go code generation tool that modifies files in GOROOT and spawns Go commands, with limited risk of abuse if run in a controlled environment.
internal/gen/code.go medium This appears to be a legitimate Go code-generation utility from the Go standard library with no data exfiltration, credential harvesting, obfuscation, process spawning, network access, or dynamic code execution; only expected file-writing behavior for code generation is present.
internal/gen/gen.go medium This appears to be a legitimate Go code generation utility from the golang.org/x/text repository that fetches Unicode/CLDR data from official sources, with only minor concerns around configurable URLs and filesystem writes that are expected for its purpose.
internal/testtext/codesize.go medium The code is a test utility that writes and compiles Go code; while it executes a compiler process and writes to a temp directory, the operations are scoped and not inherently malicious, though caution is needed if used with untrusted input.
unicode/norm/maketables.go medium This is a standard Unicode normalization table generator from the official golang.org/x/text module; it contains no malicious patterns, though as build tooling it fetches data over the network and writes generated files.
unicode/rangetable/gen.go medium This is a legitimate Go code generation tool from the golang.org/x/text repository that fetches official Unicode data and generates range tables; it poses no direct malicious threat but contains build-time network and file-write behavior worth noting.
cases/cases.go safe Cleared by Jev triage; no further analysis needed
cases/context.go safe Cleared by Jev triage; no further analysis needed
cases/fold.go safe Cleared by Jev triage; no further analysis needed
cases/gen.go safe This is a legitimate Unicode case-folding table generator from the Go standard library with no malicious patterns.
cases/gen_trieval.go safe Cleared by Jev triage; no further analysis needed
cases/info.go safe Cleared by Jev triage; no further analysis needed
cases/map.go safe No malicious patterns detected; the file contains standard Unicode case-mapping logic from golang.org/x/text with no network, filesystem, process, or dynamic execution behavior.
cases/trieval.go safe Cleared by Jev triage; no further analysis needed
cmd/gotext/common.go safe No malicious patterns detected; the code is a standard Go package loader for the gotext command-line tool with no data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
cmd/gotext/doc.go safe Cleared by Jev triage; no further analysis needed
cmd/gotext/examples/extract/catalog.go safe No malicious patterns detected; the code is a generated localization catalog using standard golang.org/x/text packages without network, filesystem, environment, or process manipulation.
cmd/gotext/examples/extract/main.go safe No malicious patterns detected
cmd/gotext/examples/extract_http/catalog_gen.go safe Code is a standard Go-generated i18n catalog with no malicious patterns detected
cmd/gotext/examples/extract_http/main.go safe No malicious patterns detected
Show 229 more files
FileVerdictWhat the reviewer saw
cmd/gotext/examples/extract_http/pkg/pkg.go safe No malicious patterns detected
cmd/gotext/examples/rewrite/main.go safe Cleared by Jev triage; no further analysis needed
cmd/gotext/examples/rewrite/printer.go safe Cleared by Jev triage; no further analysis needed
cmd/gotext/extract.go safe No malicious patterns detected
cmd/gotext/generate.go safe No malicious patterns detected
cmd/gotext/main.go safe No malicious patterns detected; this is a standard Go CLI tool for managing translations with no exfiltration, credential harvesting, dynamic code execution, or backdoor behavior.
cmd/gotext/rewrite.go safe No malicious patterns detected; the file is a standard command implementation for a source code rewriting tool from the official golang.org/x/text module.
cmd/gotext/update.go safe No malicious patterns detected
collate/build/builder.go safe Cleared by Jev triage; no further analysis needed
collate/build/colelem.go safe Cleared by Jev triage; no further analysis needed
collate/build/contract.go safe Cleared by Jev triage; no further analysis needed
collate/build/order.go safe Cleared by Jev triage; no further analysis needed
collate/build/table.go safe Cleared by Jev triage; no further analysis needed
collate/build/trie.go safe Cleared by Jev triage; no further analysis needed
collate/collate.go safe No malicious patterns detected; the code is a standard Unicode collation package with benign import-time initialization.
collate/index.go safe Cleared by Jev triage; no further analysis needed
collate/option.go safe Cleared by Jev triage; no further analysis needed
collate/sort.go safe Cleared by Jev triage; no further analysis needed
collate/tools/colcmp/col.go safe The Go file contains standard collation comparison utilities from the Go standard library with no malicious patterns, no network/file/process operations, and no install-time or dynamic code execution concerns.
collate/tools/colcmp/colcmp.go safe No malicious patterns detected
collate/tools/colcmp/darwin.go safe No malicious patterns detected; the code is a legitimate Go collator implementation using cgo to interface with macOS CoreFoundation APIs.
collate/tools/colcmp/gen.go safe Cleared by Jev triage; no further analysis needed
collate/tools/colcmp/icu.go safe No malicious patterns detected; this is a standard ICU collation wrapper from the Go standard library's collate tool, using CGO for Unicode collation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
currency/common.go safe Cleared by Jev triage; no further analysis needed
currency/currency.go safe Cleared by Jev triage; no further analysis needed
currency/format.go safe Cleared by Jev triage; no further analysis needed
currency/gen.go safe This is a legitimate Go code generator from the official golang.org/x/text repository that processes CLDR data to generate currency tables, with no malicious patterns detected.
currency/gen_common.go safe Cleared by Jev triage; no further analysis needed
currency/query.go safe Cleared by Jev triage; no further analysis needed
date/gen.go safe This is a legitimate Go code generation tool from the golang.org/x/text package that processes CLDR data; no malicious patterns detected.
doc.go safe No malicious patterns detected in the package documentation file.
encoding/charmap/charmap.go safe No malicious patterns detected
encoding/charmap/maketables.go safe This is a legitimate code generator from the golang.org/x/text package that downloads character encoding tables from trusted WHATWG/ICU sources to generate Go source code; no malicious patterns detected.
encoding/encoding.go safe Cleared by Jev triage; no further analysis needed
encoding/htmlindex/gen.go safe This is a benign Go code generator (build-ignored via //go:build ignore) that downloads WHATWG encoding data and produces a Go lookup table; no malicious patterns were found.
encoding/htmlindex/htmlindex.go safe Cleared by Jev triage; no further analysis needed
encoding/htmlindex/map.go safe Cleared by Jev triage; no further analysis needed
encoding/htmlindex/tables.go safe No malicious patterns detected
encoding/ianaindex/ascii.go safe Cleared by Jev triage; no further analysis needed
encoding/ianaindex/gen.go safe The file is a legitimate Go code generator for IANA character-set tables with no malicious patterns detected.
encoding/ianaindex/ianaindex.go safe Cleared by Jev triage; no further analysis needed
encoding/ianaindex/tables.go safe No malicious patterns detected; the file is a generated data table of IANA character encoding identifiers, aliases, and MIB mappings with no executable logic, network access, filesystem manipulation, or process spawning.
encoding/internal/enctest/enctest.go safe Cleared by Jev triage; no further analysis needed
encoding/internal/identifier/gen.go safe This is a legitimate Go code generator from the standard library's golang.org/x/text repository that parses IANA charset registry XML and generates Go source; no malicious patterns detected.
encoding/internal/identifier/identifier.go safe Cleared by Jev triage; no further analysis needed
encoding/internal/identifier/mib.go safe Cleared by Jev triage; no further analysis needed
encoding/internal/internal.go safe Cleared by Jev triage; no further analysis needed
encoding/japanese/all.go safe Cleared by Jev triage; no further analysis needed
encoding/japanese/eucjp.go safe Cleared by Jev triage; no further analysis needed
encoding/japanese/iso2022jp.go safe Cleared by Jev triage; no further analysis needed
encoding/japanese/shiftjis.go safe Cleared by Jev triage; no further analysis needed
encoding/korean/euckr.go safe Cleared by Jev triage; no further analysis needed
encoding/korean/maketables.go safe The code is a legitimate Go code generator for Korean EUC-KR encoding tables with no malicious patterns detected.
encoding/simplifiedchinese/all.go safe Cleared by Jev triage; no further analysis needed
encoding/simplifiedchinese/gbk.go safe Cleared by Jev triage; no further analysis needed
encoding/simplifiedchinese/hzgb2312.go safe Cleared by Jev triage; no further analysis needed
encoding/traditionalchinese/big5.go safe Cleared by Jev triage; no further analysis needed
encoding/unicode/override.go safe Cleared by Jev triage; no further analysis needed
encoding/unicode/unicode.go safe Cleared by Jev triage; no further analysis needed
encoding/unicode/utf32/utf32.go safe Cleared by Jev triage; no further analysis needed
feature/plural/common.go safe Cleared by Jev triage; no further analysis needed
feature/plural/gen.go safe No malicious patterns detected; this is a legitimate Go code generator for CLDR plural rules with no network, credential, or execution abuse.
feature/plural/gen_common.go safe Cleared by Jev triage; no further analysis needed
feature/plural/message.go safe Cleared by Jev triage; no further analysis needed
feature/plural/plural.go safe Cleared by Jev triage; no further analysis needed
feature/plural/tables.go safe No malicious patterns detected in the generated CLDR plural rules data tables.
internal/catmsg/catmsg.go safe No malicious patterns detected; the code is a legitimate Go text message catalog implementation with no network, filesystem, process, or obfuscation concerns.
internal/catmsg/codec.go safe No malicious patterns detected; this is a standard Go text message encoding/decoding library with no network, filesystem, process execution, or credential access.
internal/catmsg/varint.go safe Cleared by Jev triage; no further analysis needed
internal/cldrtree/cldrtree.go safe Cleared by Jev triage; no further analysis needed
internal/cldrtree/generate.go safe Cleared by Jev triage; no further analysis needed
internal/cldrtree/option.go safe Cleared by Jev triage; no further analysis needed
internal/cldrtree/testdata/test1/output.go safe No malicious patterns detected; this is a generated CLDR data file containing only static lookup tables and constants.
internal/cldrtree/testdata/test2/output.go safe No malicious patterns detected; this is a standard generated Go CLDR data table file with only static data and no network, filesystem, process, or dynamic execution behavior.
internal/cldrtree/tree.go safe Cleared by Jev triage; no further analysis needed
internal/cldrtree/type.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/collelem.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/colltab.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/contract.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/iter.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/numeric.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/table.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/trie.go safe Cleared by Jev triage; no further analysis needed
internal/colltab/weighter.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/gen.go safe This is a standard Go code generator for Unicode IDNA tables from the golang.org/x/text repository; no malicious patterns were detected.
internal/export/idna/gen_common.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/gen_trieval.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/idna.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/punycode.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/trie.go safe Cleared by Jev triage; no further analysis needed
internal/export/idna/trieval.go safe Cleared by Jev triage; no further analysis needed
internal/export/unicode/doc.go safe No malicious patterns detected
internal/export/unicode/gen.go safe This is an official Go standard library code generator with no malicious patterns; it only reads Unicode data files and generates Go source code.
internal/format/format.go safe Cleared by Jev triage; no further analysis needed
internal/format/parser.go safe Cleared by Jev triage; no further analysis needed
internal/gen/bitfield/bitfield.go safe Cleared by Jev triage; no further analysis needed
internal/internal.go safe Cleared by Jev triage; no further analysis needed
internal/language/common.go safe Cleared by Jev triage; no further analysis needed
internal/language/compact.go safe Cleared by Jev triage; no further analysis needed
internal/language/compact/compact.go safe This is a standard Go internal package from golang.org/x/text that implements compact language tag representation with no malicious patterns, network calls, process execution, or credential harvesting.
internal/language/compact/gen.go safe Legitimate Go code generator for CLDR language tag tables with no malicious patterns detected.
internal/language/compact/gen_index.go safe This is a standard Go code generation utility from the golang.org/x/text package that builds compact language tag tables; no malicious patterns, network activity, credential access, or suspicious code execution were found.
internal/language/compact/gen_parents.go safe This is a legitimate Go code generation tool that reads CLDR data and writes a parents lookup table; no malicious patterns were detected.
internal/language/compact/language.go safe Cleared by Jev triage; no further analysis needed
internal/language/compact/parents.go safe No malicious patterns detected
internal/language/compact/tables.go safe The file is a generated Go table of language tag indices and compact core info constants, containing no executable logic, network calls, credential access, or other malicious patterns.
internal/language/compact/tags.go safe Cleared by Jev triage; no further analysis needed
internal/language/compose.go safe Cleared by Jev triage; no further analysis needed
internal/language/coverage.go safe Cleared by Jev triage; no further analysis needed
internal/language/gen.go safe No malicious patterns detected; the file is a standard Go code generator for language tag tables with no external network, credential, or command execution behavior.
internal/language/gen_common.go safe Cleared by Jev triage; no further analysis needed
internal/language/language.go safe Cleared by Jev triage; no further analysis needed
internal/language/lookup.go safe Cleared by Jev triage; no further analysis needed
internal/language/match.go safe Cleared by Jev triage; no further analysis needed
internal/language/parse.go safe Cleared by Jev triage; no further analysis needed
internal/language/tags.go safe Cleared by Jev triage; no further analysis needed
internal/match.go safe Cleared by Jev triage; no further analysis needed
internal/number/common.go safe Cleared by Jev triage; no further analysis needed
internal/number/decimal.go safe This is legitimate Go standard library code for decimal number conversion and rounding with no malicious patterns detected.
internal/number/format.go safe Cleared by Jev triage; no further analysis needed
internal/number/gen.go safe No malicious patterns detected; this is a standard Go code generator for CLDR number formatting tables.
internal/number/gen_common.go safe Cleared by Jev triage; no further analysis needed
internal/number/number.go safe Cleared by Jev triage; no further analysis needed
internal/number/pattern.go safe Cleared by Jev triage; no further analysis needed
internal/number/roundingmode_string.go safe No malicious patterns detected
internal/number/tables.go safe No malicious patterns detected; this is a generated CLDR data table file from golang.org/x/text with only static numerical data and no executable logic.
internal/stringset/set.go safe Cleared by Jev triage; no further analysis needed
internal/tag/tag.go safe Cleared by Jev triage; no further analysis needed
internal/testtext/flag.go safe Cleared by Jev triage; no further analysis needed
internal/testtext/gc.go safe Cleared by Jev triage; no further analysis needed
internal/testtext/gccgo.go safe Cleared by Jev triage; no further analysis needed
internal/testtext/text.go safe Cleared by Jev triage; no further analysis needed
internal/triegen/compact.go safe Cleared by Jev triage; no further analysis needed
internal/triegen/print.go safe No malicious patterns detected; this is standard Go code generation logic for a trie data structure with no network, filesystem, or process execution activity.
internal/triegen/triegen.go safe Cleared by Jev triage; no further analysis needed
internal/ucd/ucd.go safe Cleared by Jev triage; no further analysis needed
internal/utf8internal/utf8internal.go safe Cleared by Jev triage; no further analysis needed
language/coverage.go safe Cleared by Jev triage; no further analysis needed
language/display/dict.go safe Cleared by Jev triage; no further analysis needed
language/display/display.go safe No malicious patterns detected
language/display/lookup.go safe Cleared by Jev triage; no further analysis needed
language/display/maketables.go safe This is a legitimate Go code generator for CLDR display name tables with no malicious patterns detected.
language/doc.go safe Cleared by Jev triage; no further analysis needed
language/gen.go safe No malicious patterns detected; the file is a standard Go code generator for language tag tables from CLDR data with no exfiltration, credential harvesting, obfuscation, or suspicious execution behavior.
language/language.go safe Cleared by Jev triage; no further analysis needed
language/match.go safe This is a legitimate Go language matching implementation from golang.org/x/text with no malicious patterns detected.
language/parse.go safe Cleared by Jev triage; no further analysis needed
language/tables.go safe No malicious patterns detected; the file contains only generated CLDR language data tables and constants from golang.org/x/text.
language/tags.go safe Cleared by Jev triage; no further analysis needed
message/catalog.go safe Cleared by Jev triage; no further analysis needed
message/catalog/catalog.go safe Cleared by Jev triage; no further analysis needed
message/catalog/dict.go safe Cleared by Jev triage; no further analysis needed
message/doc.go safe Cleared by Jev triage; no further analysis needed
message/format.go safe Cleared by Jev triage; no further analysis needed
message/message.go safe Cleared by Jev triage; no further analysis needed
message/pipeline/extract.go safe No malicious patterns detected; this is a standard Go source extraction tool for i18n message extraction without any exfiltration, credential harvesting, or dynamic code execution.
message/pipeline/generate.go safe No malicious patterns detected; the code is a legitimate Go code generator for i18n message catalogs with no network, credential access, or dynamic execution.
message/pipeline/message.go safe Cleared by Jev triage; no further analysis needed
message/pipeline/pipeline.go safe No malicious patterns detected; the code is a legitimate Go text translation pipeline tool with no network, credential harvesting, obfuscation, or process execution behavior.
message/pipeline/rewrite.go safe No malicious patterns detected; this is a legitimate Go source-rewriting tool from the golang.org/x/text repository that performs static AST transformations and file writes only to explicitly targeted Go source files.
message/pipeline/testdata/ssa/catalog_gen.go safe No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior.
message/pipeline/testdata/ssa/ssa.go safe Cleared by Jev triage; no further analysis needed
message/pipeline/testdata/test1/test1.go safe Cleared by Jev triage; no further analysis needed
message/pipeline/testdata/test60555/catalog_gen.go safe No malicious patterns detected; this is a generated Go file implementing a standard i18n message catalog with empty dictionary and no external I/O, process spawning, or obfuscated behavior.
message/pipeline/testdata/test60555/main.go safe Cleared by Jev triage; no further analysis needed
message/pipeline/testdata/test60555/message.go safe Cleared by Jev triage; no further analysis needed
message/print.go safe Cleared by Jev triage; no further analysis needed
number/doc.go safe Cleared by Jev triage; no further analysis needed
number/format.go safe Cleared by Jev triage; no further analysis needed
number/number.go safe Cleared by Jev triage; no further analysis needed
number/option.go safe Cleared by Jev triage; no further analysis needed
runes/cond.go safe Cleared by Jev triage; no further analysis needed
runes/runes.go safe Cleared by Jev triage; no further analysis needed
search/index.go safe Cleared by Jev triage; no further analysis needed
search/pattern.go safe Cleared by Jev triage; no further analysis needed
search/search.go safe This is a legitimate Go text search package from golang.org/x/text with no malicious patterns, network activity, or suspicious behavior.
secure/bidirule/bidirule.go safe The file implements RFC 5893 Bidi Rule validation with only local Unicode processing; no malicious patterns detected.
secure/doc.go safe Cleared by Jev triage; no further analysis needed
secure/precis/class.go safe Cleared by Jev triage; no further analysis needed
secure/precis/context.go safe No malicious patterns detected; the code implements PRECIS contextual rules with table-driven logic and an init function that only configures local bitmasks.
secure/precis/doc.go safe No malicious patterns detected
secure/precis/gen.go safe No malicious patterns detected; this is a standard Go code generator for Unicode tables with build tag 'ignore' and no runtime execution.
secure/precis/gen_trieval.go safe Cleared by Jev triage; no further analysis needed
secure/precis/nickname.go safe Cleared by Jev triage; no further analysis needed
secure/precis/options.go safe Cleared by Jev triage; no further analysis needed
secure/precis/profile.go safe Cleared by Jev triage; no further analysis needed
secure/precis/profiles.go safe Cleared by Jev triage; no further analysis needed
secure/precis/transformer.go safe Cleared by Jev triage; no further analysis needed
secure/precis/trieval.go safe Cleared by Jev triage; no further analysis needed
transform/transform.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/bidi.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/bracket.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/core.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/gen.go safe This is a legitimate Go code generator from the official golang.org/x/text repository that generates Unicode bidirectional text tables and contains no malicious patterns.
unicode/bidi/gen_ranges.go safe No malicious patterns detected; the file is a standard Go code generator for Unicode bidi ranges with no network, credential, or execution risks.
unicode/bidi/gen_trieval.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/prop.go safe Cleared by Jev triage; no further analysis needed
unicode/bidi/trieval.go safe No malicious patterns detected in the Go source file; it contains only standard Unicode bidirectional class definitions and constants.
unicode/cldr/base.go safe Cleared by Jev triage; no further analysis needed
unicode/cldr/cldr.go safe Cleared by Jev triage; no further analysis needed
unicode/cldr/collate.go safe Cleared by Jev triage; no further analysis needed
unicode/cldr/decode.go safe No malicious patterns detected
unicode/cldr/makexml.go safe No malicious patterns detected; this is a standard Go code generation tool from the official Go source tree that reads CLDR DTD zip data and writes Go XML type definitions.
unicode/cldr/resolve.go safe Cleared by Jev triage; no further analysis needed
unicode/cldr/slice.go safe Cleared by Jev triage; no further analysis needed
unicode/cldr/xml.go safe This is a generated Go struct definition file for parsing CLDR XML data, containing no executable logic, network calls, or malicious patterns.
unicode/doc.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/composition.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/forminfo.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/input.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/iter.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/normalize.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/readwriter.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/transform.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/trie.go safe Cleared by Jev triage; no further analysis needed
unicode/norm/triegen.go safe Cleared by Jev triage; no further analysis needed
unicode/rangetable/merge.go safe Cleared by Jev triage; no further analysis needed
unicode/rangetable/rangetable.go safe Cleared by Jev triage; no further analysis needed
unicode/runenames/gen.go safe This is a benign Go code generation tool from the official golang.org/x/text repository that processes Unicode character data to generate lookup tables, with no malicious patterns detected.
unicode/runenames/runenames.go safe Cleared by Jev triage; no further analysis needed
width/gen.go safe No malicious patterns detected
width/gen_common.go safe This is a standard Go code generator file from the official golang.org/x/text repository with no malicious patterns; it only reads Unicode data files for width table generation.
width/gen_trieval.go safe Cleared by Jev triage; no further analysis needed
width/kind_string.go safe This is a standard Go stringer-generated file containing only constant name and index tables with no network, filesystem, process, or dynamic code execution activity.
width/tables15.0.0.go safe No malicious patterns detected; the file is generated Unicode width table data with only static lookup functions.
width/tables17.0.0.go safe No malicious patterns detected; this is a standard generated Unicode width lookup table with no network, filesystem, process, or dynamic code execution behavior.
width/transform.go safe Cleared by Jev triage; no further analysis needed
width/trieval.go safe Cleared by Jev triage; no further analysis needed
width/width.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is golang.org/x/text safe to use?

No confirmed malware was found in golang.org/x/text@v0.42.0, but the review flagged 7 medium, 31 low severity findings for risky patterns worth checking before you rely on it.

Does golang.org/x/text contain malware?

No malware was identified in golang.org/x/text@v0.42.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was golang.org/x/text checked?

Togoder Security downloaded the published Go package and had an AI model read its 254 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan golang.org/x/text together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/text@v0.42.0, cost nothing.

Related security reports