Summary
Togoder Security scanned the Go package google.golang.org/grpc@v1.84.0 on Oct 5, 2026. An AI review of 545 source files produced 16 medium, 41 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 57
Insecure file permissions / privilege escalation risk
NPS-F9362819EA81
The FileWatcherInterceptor reads a policy file from an arbitrary path specified via PolicyFile option. If the process has elevated privileges and the path is attacker-controlled, this could allow reading sensitive files outside the intended package scope. While it is a legitimate feature for loading authz policies, the code does not validate or restrict the file path, potentially enabling information disclosure if an attacker can influence the configuration.
Unbounded resource consumption
NPS-DDB4DEA6B260
The RunServer/RunClient handlers accept repeated setup requests, each closing previous instances and starting new ones, which could be abused for resource exhaustion if the port is reachable.
Network listener on all interfaces
NPS-4B5CF06F2ADD
The worker listens on all network interfaces (':<driverPort>') without authentication, allowing any host that can reach the port to control benchmark servers/clients and potentially exhaust resources.
File system manipulation outside package scope
NPS-0B36D64844CB
NewTempFileSink creates a temporary file in /tmp using a predictable prefix 'grpcgo_binarylog_*.txt'. Writing potentially sensitive gRPC binary log data (which can include headers, metadata, and message contents) to a world-readable directory like /tmp could lead to information disclosure to other local users or processes on the system.
Disabled ALPN verification
NPS-EE72DFBB9F05
The entire package purposefully disables ALPN verification (NewTLSWithALPNDisabled, NewClientTLSFromCertWithALPNDisabled, etc.). ALPN is the mechanism that ensures the negotiated protocol matches expectations; disabling it weakens TLS/HTTP2 security guarantees and can enable protocol downgrade or cross-protocol attacks. The package documentation itself states use is strongly discouraged.
TLS verification bypass
NPS-B59AD0F1589E
When a SPIFFE bundle map is present, the code disables standard TLS certificate verification (InsecureSkipVerify: true) and delegates validation to a custom verify function. While this is an intentional design for SPIFFE-based trust, misuse or misconfiguration could lead to accepting untrusted certificates if the custom verification logic is flawed or bypassed.
Unbounded regex compilation from external input
NPS-CC5337A3C43E
StringMatcherFromProto compiles regex patterns received over the network from the xDS management server with regexp.Compile. Malicious or compromised xDS servers can supply pathological patterns that are resource-intensive to compile or execute.
ReDoS (Regular Expression Denial of Service) risk
NPS-A374E9F8DB99
CompileSafeRegex anchors and compiles user-supplied patterns from xDS protos without complexity limits or timeouts. Crafted regexes (e.g., nested quantifiers like '(a+)+$') can cause catastrophic backtracking, leading to CPU exhaustion and denial of service in the gRPC/xDS control plane or data path when matching strings.
Shell command execution from user-controlled input
NPS-3B1964C5908C
runCmd() executes a user-supplied command string via exec.Command("bash", "-c", command).Run(). The value comes from the --induce_fallback_cmd flag, allowing arbitrary shell command execution when the binary is run. This is typical for an interop/test harness but still represents a command injection surface if the binary is invoked with attacker-controlled flags.
Credential exposure in logs
NPS-5E15D9F9D355
Multiple error messages (e.g., DoServiceAccountCreds, DoJWTTokenCreds, DoOauth2TokenCreds, DoPerRPCCreds) log the contents of the service account JSON key file via logger.Fatalf when the username doesn't match. This could leak credential material into logs.
Unsafe deserialization
NPS-051B87E5EA67
The code uses gob.Decode to deserialize the contents of an arbitrary file path provided via the -snapshot flag. If an attacker can supply a malicious gob-encoded file, this could potentially lead to unexpected behavior or resource exhaustion, although gob is generally considered safer than some other serialization formats. The file path is user-controlled.
Arbitrary file write via user-supplied path
NPS-87F103A055BD
The retrieveSnapshot function creates a file using the path provided by the user via *flagSnapshot. An attacker controlling command-line arguments could write a gob-encoded snapshot to an arbitrary location on the filesystem, potentially overwriting sensitive files or placing files in unintended directories.
Insecure network transport
NPS-21A421D32783
The code uses grpc.WithTransportCredentials(insecure.NewCredentials()), which disables TLS encryption for the gRPC connection. This means all profiling data and commands sent to the remote server are transmitted in plaintext, potentially exposing sensitive runtime information to attackers on the network.
Remote control of profiling subsystem
NPS-3537850EEFBD
The Enable RPC allows any client with access to the gRPC server to remotely enable or disable profiling without authentication or authorization checks. This could be abused to cause resource exhaustion or information disclosure if the profiling service is exposed to untrusted networks.
In-memory data exposure via profiling stats
NPS-418D3C7EE4E9
GetStreamStats exposes detailed runtime profiling data (tags, timers, metadata) through an unauthenticated RPC. If the gRPC server is reachable by untrusted parties, this leaks internal timing, call metadata, and potentially sensitive contextual information about RPCs.
Environment variable usage
NPS-73D7A09BAD69
Reads environment variable C2PResolverTestOnlyTrafficDirectorURI via envconfig to override the Traffic Director URI. If an attacker can control this environment variable, they could redirect traffic to a malicious server. However, this is intended for testing and is guarded by a configuration flag.
Use of unsafe package
NPS-A66045E607CB
The code uses unsafe.Pointer and atomic.StorePointer/LoadPointer for updating the internal interceptor. While this is a known pattern for lock-free atomic updates, it bypasses Go's type safety and could lead to memory corruption if misused. However, in this context it appears correct and intentional.
Information leakage via logging
NPS-BB6C084ED334
The full policy content is logged at info level (logger.Infof) when a policy is successfully reloaded. This could expose sensitive authorization rules in logs, which might be accessible to unauthorized parties.
File System Write Outside Package Scope
NPS-38DF45E0099D
The program creates CPU and memory profile files directly in /tmp/ using the user-supplied -test_name flag, which could allow writing files to arbitrary paths if the test name contains path traversal sequences (e.g., ../). This is a local, user-controlled benchmark utility, so the risk is limited.
Insecure Transport Configuration
NPS-FF7141D9FB4C
The client connects to the server using insecure transport credentials (grpc.WithTransportCredentials(insecure.NewCredentials())). While expected for a local benchmark tool, it would be insecure if used in production or against untrusted networks.
network listener
NPS-B7B48E1979E9
The server listens on a TCP port for incoming gRPC connections. This is the intended purpose of the benchmark server and not a security concern.
file system write
NPS-A73484090CE7
The program writes CPU and memory profiles to /tmp using a filename derived from the user-supplied -test_name flag. This is expected behavior for a benchmark server and does not indicate malicious intent. However, a non-sanitized test name could theoretically allow path traversal, though this is a local dev tool and not a security boundary.
Debug pprof endpoint exposure
NPS-E3B0D6AE8B74
When pprof_port is specified, an HTTP pprof debug server is started. Although bound to localhost, pprof endpoints can leak runtime details and in some contexts may aid further exploitation.
Insecure temporary file handling
NPS-D7959FE53591
The function uses os.CreateTemp which is generally safe against race conditions, but the use of a fixed, predictable directory (/tmp) and predictable filename pattern means an attacker with local access could potentially monitor or access these temp files. The sink is explicitly designed to log binary data that may contain sensitive information.
Environment/platform detection
NPS-1654E1B5CAC8
The code checks whether it is running on Google Cloud Platform (GCE) via googlecloud.OnGCE() before proceeding with ALTS handshakes. This is expected behavior for ALTS credentials and not credential harvesting.
Network communication
NPS-7FCEAEA443F0
Connects to the ALTS handshaker service at a default GCP-internal address (dns:///metadata.google.internal.:8080) or a user-provided address. This is the documented purpose of the package and not exfiltration.
init() function usage
NPS-FAE57B246E2B
The package uses an init() function to initialize global variables (backoff strategy and ID token credentials constructor). This is a standard Go pattern for package initialization and does not perform any suspicious network, file system, or process operations. The initialized functions are only invoked later when explicitly creating credentials.
ServerName override via OverrideServerName
NPS-4908A29BECE7
OverrideServerName directly mutates c.config.ServerName without validation. If called on a shared config it could redirect certificate verification to an attacker-controlled name. The method is part of the standard TransportCredentials interface, but mutation of the underlying config is a latent risk.
Potential weak cipher suite inclusion
NPS-B6F3653E8C39
applyDefaults adds all cipher suites reported by tls.CipherSuites() except those explicitly forbidden by RFC 7540 Appendix A. tls.CipherSuites() returns 'secure' suites in modern Go, but the allow-list approach combined with disabled ALPN may still permit suites that are inappropriate for the intended HTTP/2 usage context.
Unrestricted certificate file read
NPS-08A657F7242E
NewClientTLSFromFileWithALPNDisabled and NewServerTLSFromFileWithALPNDisabled read arbitrary file paths supplied by the caller via os.ReadFile / tls.LoadX509KeyPair. This is expected for credential-loading APIs but could be abused if paths are attacker-influenced; no path sanitization is performed.
import-time side effect
NPS-BEFC496AB53A
The init() function registers a glog-based logger as the global grpclog logger. This is intended package behavior documented in the package comment, not malicious. It has no network, filesystem, credential, or execution capabilities beyond routing log messages.
Environment variable usage
NPS-22F854BA866C
Package documentation references GRPC_GO_LOG_SEVERITY_LEVEL and GRPC_GO_LOG_VERBOSITY_LEVEL environment variables for configuring logging. These are legitimate gRPC logging configuration variables, not credential harvesting.
Process termination
NPS-97D8F5DA7146
Fatal/Fatalf/Fatalln/FatalDepth functions call os.Exit(1). This is standard logging behavior for fatal-level logs in Go's grpclog package, not a backdoor or malicious process spawn.
Code runs at import time
NPS-66001C8DDBDC
The init() function executes automatically when the package is imported, reading environment variables and initializing the global binary logger. While this is standard Go practice and the action is benign (only configuration parsing), it does constitute import-time code execution.
Environment variable harvesting
NPS-34A5DDFCB214
The init() function reads the GRPC_BINARY_LOG_FILTER environment variable at import time and uses it to configure binary logging behavior. This is a legitimate gRPC feature for logging filter configuration, but it means any process importing this package will read this environment variable at startup.
Environment variable controlled security behavior
NPS-6C23BDBD4D58
The code checks envconfig.XDSSNIEnabled to conditionally change SNI and SAN validation behavior. This is not credential harvesting or exfiltration; it is a standard gRPC xDS feature flag. No malicious environment variable reading for secrets was observed.
Testing hook registered in init()
NPS-B97EEF960015
The init() function sets internal.GetXDSHandshakeInfoForTesting = HandshakeInfoFromAttributes. This runs at package import time but only wires an internal testing hook and does not perform any network, filesystem, or process operations. It is benign for this gRPC package.
Custom certificate verification with InsecureSkipVerify
NPS-2211735B88E3
The client-side TLS config sets InsecureSkipVerify to true, disabling Go's built-in hostname and certificate chain verification. While this is intentional to perform custom SAN verification via VerifyPeerCertificate, it is a security-sensitive pattern that could allow MITM if the custom verification logic has flaws. In this code the custom function does chain verification and SAN matching, so it is not malicious.
Environment variable reading
NPS-C1394415DBC9
This code reads numerous GRPC_* environment variables to configure gRPC behavior. This is the intended, documented purpose of the file. The environment variables are configuration knobs specific to gRPC (TXT service config, ring hash cap, ALTS handshake limits, header list size, etc.) and do not involve harvesting credentials, tokens, or secrets.
Package-level variable initialization
NPS-25894A051D65
The file uses package-level var initialization to read environment variables at import time. This is normal Go practice for configuration and matches the file's stated purpose. The values are parsed safely via strconv.ParseUint and string comparisons; no external calls, file access, or code execution occur.
standard protobuf initialization code
NPS-1A6E18B45C6B
The init() function performs standard protobuf registration and descriptor building only. No external calls, file I/O, network access, or process spawning occurs.
unsafe pointer usage for gzip compression
NPS-6E7CA33C7713
Uses unsafe.Slice/unsafe.StringData to compress the embedded proto descriptor. This is standard generated code from protoc-gen-go for efficiency; the data is a static compile-time constant, not attacker-controlled.
File system manipulation
NPS-2349B6BF63EE
The code creates temporary directories and copies certificate/key files into them for use in end-to-end tests. This is normal test utility behavior and does not access sensitive user files or locations outside the test scope.
Use of os.ModePerm
NPS-8278288386BD
Files are written with permission 0777 (os.ModePerm), which is overly permissive. However, these are temporary test files in a temporary directory and not a security risk in this context.
Environment variable gating
NPS-16EC04B3F55E
The SPIFFE trust bundle map file functionality is gated behind the environment variable XDSSPIFFEEnabled. If not explicitly enabled, the feature is disabled by clearing the config field. This is not malicious but could be used to conditionally activate functionality based on environment, which might be unexpected in a security-sensitive context.
weak parsing with Sscanf
NPS-269ECFB133C1
LocalityFromString uses fmt.Sscanf with %q format specifiers to parse locality strings. While not a direct security vulnerability, format-string-based parsing can be fragile and may not handle malformed or adversarial inputs robustly. No direct exploit is evident.
init function execution at import time
NPS-EDE614A6D6C2
The init() function runs automatically when the package is imported. It registers a callback function via internal.AddressToTelemetryLabels. While this is standard Go practice for package initialization and the assignment itself is benign, it constitutes top-level code execution at import time that modifies global state. In this specific case the callback only returns telemetry labels derived from resolver addresses, but init() functions are a common vector for malicious code and warrant examination.
Dynamic import / balancer registration
NPS-173E850CE76F
Imports with blank identifiers (_ "google.golang.org/grpc/balancer/grpclb" and _ "google.golang.org/grpc/xds/googledirectpath") trigger side-effect init() functions in those packages. This is expected gRPC behavior, but blank-import side effects are a common vector for hidden initialization logic.
Raw socket option manipulation
NPS-92906130C709
dialTCPUserTimeout uses syscall.RawConn.Control to set TCP_USER_TIMEOUT via unix.SetsockoptInt, and calls errorLog.Fatalf on error. Uses Fatal inside a Control callback (goroutine context) rather than returning the error, which can terminate the process unexpectedly. Not malicious, but low-level socket manipulation warrants noting.
insecure gRPC connection
NPS-1D7E44D49D18
The client uses insecure.NewCredentials() to connect to the metrics server, meaning the connection is unencrypted. This is a security best-practice concern but not a malicious pattern; it is common in test/interop tooling.
Test-only package with fatal exits
NPS-152CD413E0D0
The package is explicitly for gRPC interop testing and uses logger.Fatalf extensively rather than returning errors. If imported and invoked outside a test context, it would terminate the process. Not malicious, but unsafe for production use.
Credential file reading
NPS-57CA5C6B8459
The getServiceAccountJSONKey function reads arbitrary files from the filesystem based on a parameter passed at runtime (serviceAccountKeyFile). It is used to read Google service account JSON keys, which contain private credentials. This is legitimate for interop testing but represents a pattern that reads sensitive credential files from disk.
global mutable state
NPS-BD9F112E1C64
The package maintains a package-level variable defaultBufferPool that can be arbitrarily reassigned via internal.SetDefaultBufferPool. If an attacker gains control of any dependency that imports this package, they could replace the buffer pool with a malicious implementation (e.g., one that returns buffers containing attacker-controlled data or that exfiltrates data via Put). This is a latent supply-chain risk rather than a direct malicious pattern.
init-time code execution
NPS-0AA76F8FC6A2
The init() function runs automatically at import time and initializes a default buffer pool. It also registers a callback (internal.SetDefaultBufferPool) that allows replacing the global default buffer pool. While the code itself is not malicious, the init() pattern is a red flag because such hooks can be abused to inject behavior at import time. The SetDefaultBufferPool hook could be repurposed by a malicious package to replace the pool with one that leaks or corrupts data.
import-time code execution
NPS-E81277627BE8
The init() function registers a parser with the balancer load subsystem. This is expected behavior for a library that needs to register itself, and the parser only reads metadata to generate load reports locally. There is no network, filesystem, or process activity.
Network request to metadata server
NPS-C37CC8A535DA
Makes HTTP requests to the GCE metadata server (http://metadata.google.internal) to retrieve instance zone and IPv6 capabilities. While this is a standard GCE metadata call, it could be abused to leak instance metadata if the code were modified by an attacker, though the current usage is legitimate.
Dynamic resolver configuration
NPS-68D431CE8F1F
Constructs xDS bootstrap configuration dynamically based on environment (GCE detection, metadata, universe domain) and creates a gRPC resolver. This dynamic behavior could be exploited if an attacker can influence the environment, but the code follows expected patterns for the library.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| authz/grpc_authz_server_interceptors.go | medium | The code is a legitimate gRPC authorization interceptor with no clear malicious intent, but it has minor security concerns related to file path handling, logging of policy content, and unsafe pointer usage. |
| benchmark/worker/main.go | medium | The benchmark worker is a legitimate gRPC testing utility but exposes an unauthenticated network control interface and optional pprof debug endpoint, posing resource exhaustion and information disclosure risks if reachable by untrusted parties. |
| binarylog/sink.go | medium | The code is part of the official gRPC-Go library and appears benign, but it writes binary log data (potentially containing sensitive information) to temporary files in /tmp, which presents a moderate information disclosure risk if used in multi-user environments. |
| experimental/credentials/tls.go | medium | This is a legitimate gRPC-Go experimental credentials package, but its deliberate disabling of ALPN verification weakens TLS security guarantees and the API surface introduces minor risks around server-name override and arbitrary file path reads. |
| internal/binarylog/binarylog.go | medium | This appears to be a legitimate gRPC binary logging implementation with no malicious patterns; the only concerns are benign import-time environment variable reading and initialization typical of Go libraries. |
| internal/xds/bootstrap/tlscreds/bundle.go | medium | The code implements mTLS credentials for xDS with SPIFFE support, but disables standard TLS verification when using SPIFFE bundles, relying on custom verification logic, which poses a medium risk if misconfigured. |
| internal/xds/matcher/string_matcher.go | medium | No overt malicious code (no exfiltration, credential harvesting, backdoors, or dynamic execution) was found; the only concerns are standard ReDoS and resource-exhaustion risks inherent in compiling and evaluating externally supplied regular expressions from xDS configuration. |
| internal/xds/xds.go | medium | This is legitimate gRPC xDS utility code with no malicious patterns; the only notable item is a standard Go init() function that registers an internal callback, which is benign here but is a common pattern for import-time code execution. |
| interop/grpclb_fallback/client_linux.go | medium | This is a legitimate gRPC interop test client from the official grpc-go repository; the only notable concern is intentional shell command execution via the --induce_fallback_cmd flag, which is standard for its test-harness purpose but should be treated with caution. |
| interop/test_utils.go | medium | This is a legitimate gRPC interop testing utility from the official grpc-go repository; it reads credential files and logs them on failure, but exhibits no malicious exfiltration, backdoor, or obfuscation patterns. |
| mem/buffer_pool.go | medium | The code is a legitimate gRPC buffer pool implementation with no malicious patterns, but its init-time global registration hook and mutable default pool present low-severity supply-chain concerns. |
| profiling/cmd/local.go | medium | The code appears to be a legitimate gRPC profiling tool with no obvious malicious patterns, but it deserializes a user-specified file using gob, which could be a security concern if untrusted input is processed. |
| profiling/cmd/remote.go | medium | The Go file is a legitimate gRPC profiling client but has security weaknesses: it uses insecure gRPC transport (no TLS) and writes a snapshot file to a user-controlled path, which could lead to plaintext data exposure or arbitrary file writes. |
| profiling/service/service.go | medium | No malicious code patterns were found, but the profiling service exposes unauthenticated RPCs that allow remote enabling/disabling of profiling and retrieval of internal runtime statistics, which could be abused if the server is exposed. |
| xds/googledirectpath/googlec2p.go | medium | The code appears to be a legitimate gRPC resolver for Google DirectPath, with expected metadata server calls and environment variable usage; no malicious patterns were found, but potential misuse of environment variables and metadata endpoints warrants a warning. |
| admin/admin.go | safe | No malicious patterns detected; the code is a legitimate gRPC admin service registration package. |
| attributes/attributes.go | safe | Cleared by Jev triage; no further analysis needed |
| authz/audit/audit_logger.go | safe | Cleared by Jev triage; no further analysis needed |
| authz/audit/stdout/stdout_logger.go | safe | Legitimate gRPC authorization audit logger that writes audit events to stdout; no malicious patterns detected. |
| authz/rbac_translator.go | safe | No malicious patterns detected; the file is a legitimate gRPC authz policy translator with no exfiltration, credential harvesting, dynamic execution, or other red flags. |
| backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| backoff/backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/balancer.go | safe | This is the official gRPC-Go balancer package containing standard interfaces and registration logic with no malicious patterns detected. |
| balancer/base/balancer.go | safe | No malicious patterns detected; this is the standard gRPC-Go base balancer implementation with no external network calls, credential access, or dynamic code execution. |
| balancer/base/base.go | safe | Cleared by Jev triage; no further analysis needed |
Show 520 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| balancer/conn_state_evaluator.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/endpointsharding/endpointsharding.go | safe | No malicious patterns detected; the code is a legitimate gRPC load balancing policy with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| balancer/grpclb/grpc_lb_v1/load_balancer.pb.go | safe | This is a standard auto-generated protobuf file from the official gRPC library containing only message definitions and serialization metadata with no malicious patterns. |
| balancer/grpclb/grpc_lb_v1/load_balancer_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/grpclb/grpclb.go | safe | No malicious patterns detected; the file is the official gRPC-Go grpclb balancer implementation with standard network, resolver, and credential handling consistent with its documented purpose. |
| balancer/grpclb/grpclb_config.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/grpclb/grpclb_picker.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/grpclb/grpclb_remote_balancer.go | safe | This is a legitimate gRPC load balancer implementation from the official Google gRPC-Go library with no malicious patterns detected. |
| balancer/grpclb/grpclb_util.go | safe | No malicious patterns detected; the code implements a gRPC load balancer SubConn cache with standard synchronization and lifecycle handling. |
| balancer/grpclb/state/state.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/lazy/lazy.go | safe | No malicious patterns detected; this is a legitimate gRPC lazy load balancer implementation from the official gRPC-Go library. |
| balancer/leastrequest/leastrequest.go | safe | This is a standard gRPC least-request load balancer implementation with no malicious patterns, external calls, or suspicious behavior. |
| balancer/pickfirst/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/pickfirst/pickfirst.go | safe | No malicious patterns detected; this is a legitimate gRPC pick_first load balancer implementation with only standard library and gRPC-internal package imports and no suspicious behavior. |
| balancer/randomsubsetting/randomsubsetting.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/ringhash/config.go | safe | No malicious patterns detected; the code is a standard gRPC ringhash load balancer configuration parser with proper input validation. |
| balancer/ringhash/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/ringhash/picker.go | safe | No malicious patterns detected; the code implements gRPC ringhash load balancing logic with no exfiltration, credential harvesting, obfuscation, or process execution. |
| balancer/ringhash/ring.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/ringhash/ringhash.go | safe | This is a legitimate gRPC ring hash balancer implementation from the official google.golang.org/grpc package with no malicious patterns detected. |
| balancer/rls/balancer.go | safe | No malicious patterns detected in the gRPC RLS balancer implementation; all imports and operations are standard for its intended load-balancing functionality. |
| balancer/rls/cache.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/rls/child_policy.go | safe | No malicious patterns detected; the code is a legitimate gRPC balancer child policy wrapper with reference counting and atomic state management. |
| balancer/rls/config.go | safe | No malicious patterns detected; the file is a legitimate gRPC RLS balancer config parser with proper input validation and no external data exfiltration, credential harvesting, dynamic code execution, or backdoor behavior. |
| balancer/rls/control_channel.go | safe | This is legitimate gRPC RLS control channel code from the official grpc-go library with no malicious patterns, no credential harvesting, no exfiltration, and no obfuscation. |
| balancer/rls/internal/adaptive/adaptive.go | safe | No malicious patterns detected; this is a legitimate adaptive throttling implementation from the gRPC-Go library with no external network calls, credential access, code execution, or obfuscation. |
| balancer/rls/internal/adaptive/lookback.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/rls/internal/keys/builder.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/rls/picker.go | safe | No malicious patterns detected; the code is a legitimate part of gRPC's Route Lookup Service balancer with no security concerns. |
| balancer/roundrobin/roundrobin.go | safe | This is a legitimate gRPC round-robin balancer implementation with no malicious patterns detected. |
| balancer/subconn.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedroundrobin/balancer.go | safe | This is a standard gRPC weighted round-robin load balancer implementation with no malicious patterns, external data exfiltration, credential harvesting, or suspicious behavior detected. |
| balancer/weightedroundrobin/config.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedroundrobin/internal/internal.go | safe | No malicious patterns detected; the code only defines test hooks for a gRPC balancer, with no network, file, process, or obfuscated behavior. |
| balancer/weightedroundrobin/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedroundrobin/scheduler.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedtarget/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedtarget/weightedaggregator/aggregator.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer/weightedtarget/weightedtarget.go | safe | No malicious patterns detected; this is a legitimate gRPC weighted target balancer implementation. |
| balancer/weightedtarget/weightedtarget_config.go | safe | Cleared by Jev triage; no further analysis needed |
| balancer_wrapper.go | safe | No malicious patterns detected; this is standard gRPC balancer wrapper code with legitimate networking and state management logic. |
| benchmark/benchmain/main.go | safe | No malicious patterns detected; the code is a standard gRPC benchmarking tool with legitimate file I/O for profiling and results, and no data exfiltration, credential harvesting, obfuscation, or suspicious process execution. |
| benchmark/benchmark.go | safe | This is a legitimate gRPC benchmark package from the official google.golang.org/grpc repository with no malicious patterns detected. |
| benchmark/benchresult/main.go | safe | Cleared by Jev triage; no further analysis needed |
| benchmark/client/main.go | safe | The code is a legitimate gRPC benchmark client with no malicious patterns; the only minor concerns are insecure transport usage and profiling files written to /tmp based on user input. |
| benchmark/flags/flags.go | safe | Cleared by Jev triage; no further analysis needed |
| benchmark/latency/latency.go | safe | No malicious patterns detected; the code is a benign gRPC latency injection benchmark utility. |
| benchmark/server/main.go | safe | The code is a legitimate gRPC benchmarking server with no malicious patterns; it only performs profiling and listens on a local port. |
| benchmark/stats/curve.go | safe | Cleared by Jev triage; no further analysis needed |
| benchmark/stats/histogram.go | safe | Cleared by Jev triage; no further analysis needed |
| benchmark/stats/stats.go | safe | Cleared by Jev triage; no further analysis needed |
| benchmark/worker/benchmark_client.go | safe | This is a standard gRPC benchmark client from the official google.golang.org/grpc repository with no malicious patterns; all network, file, and process usage is consistent with its benchmarking purpose. |
| benchmark/worker/benchmark_server.go | safe | No malicious patterns detected; the file is part of the official gRPC-Go benchmark worker and only implements a TLS-capable benchmark server with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| binarylog/grpc_binarylog_v1/binarylog.pb.go | safe | This is a standard protoc-gen-go generated file for gRPC binary logging protobuf definitions, containing only boilerplate message types, enum definitions, and protobuf reflection registration with no malicious patterns. |
| call.go | safe | No malicious patterns detected; the code is standard gRPC client invocation logic from the official gRPC-Go package with no exfiltration, obfuscation, credential harvesting, or other suspicious behavior. |
| channelz/channelz.go | safe | No malicious patterns detected; the file only re-exports an identifier type from an internal gRPC package. |
| channelz/grpc_channelz_v1/channelz_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/internal/protoconv/channel.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/internal/protoconv/server.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/internal/protoconv/socket.go | safe | No malicious patterns detected; this is a legitimate gRPC channelz protobuf conversion utility with no external data transmission, credential harvesting, or code execution. |
| channelz/internal/protoconv/sockopt_linux.go | safe | No malicious patterns detected |
| channelz/internal/protoconv/sockopt_nonlinux.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/internal/protoconv/subchannel.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/internal/protoconv/util.go | safe | Cleared by Jev triage; no further analysis needed |
| channelz/service/service.go | safe | No malicious patterns detected; code is a legitimate gRPC channelz service implementation from the official google.golang.org/grpc module. |
| clientconn.go | safe | No malicious patterns detected |
| clientconn_disconnect_reason_noplan9.go | safe | No malicious patterns detected |
| clientconn_disconnect_reason_plan9.go | safe | Cleared by Jev triage; no further analysis needed |
| codec.go | safe | Cleared by Jev triage; no further analysis needed |
| codes/code_string.go | safe | Cleared by Jev triage; no further analysis needed |
| codes/codes.go | safe | Cleared by Jev triage; no further analysis needed |
| connectivity/connectivity.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/alts.go | safe | This is a legitimate gRPC ALTS credentials implementation with no malicious patterns; network connections and platform checks are inherent to its documented security functionality. |
| credentials/alts/internal/authinfo/authinfo.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/common.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/conn/aeadrekey.go | safe | This is a legitimate gRPC ALTS rekey AEAD implementation with no malicious patterns; it uses standard cryptographic primitives for encryption and key derivation without any exfiltration, backdoors, or suspicious behavior. |
| credentials/alts/internal/conn/aes128gcm.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/conn/aes128gcmrekey.go | safe | This file contains standard cryptographic implementation for gRPC ALTS record layer using AES128-GCM with rekeying, with no malicious patterns, network calls, process spawning, file system access, or dynamic code execution. |
| credentials/alts/internal/conn/common.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/conn/counter.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/conn/record.go | safe | This is a legitimate gRPC ALTS record protocol implementation with no malicious patterns detected. |
| credentials/alts/internal/conn/utils.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/handshaker/handshaker.go | safe | No malicious patterns detected; the code is a legitimate gRPC ALTS handshaker implementation with proper bounds checking and no data exfiltration or backdoors. |
| credentials/alts/internal/handshaker/service/service.go | safe | No malicious patterns detected; the code manages ALTS handshaker gRPC connections using standard connection pooling and insecure credentials only for a local VM-to-hypervisor channel. |
| credentials/alts/internal/proto/grpc_gcp/altscontext.pb.go | safe | This is a standard protoc-gen-go generated file for ALTS context definitions with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| credentials/alts/internal/proto/grpc_gcp/handshaker.pb.go | safe | No malicious patterns detected; this is a standard protoc-generated Go file defining gRPC ALTS handshaker protobuf types with no executable network, file system, or process operations. |
| credentials/alts/internal/proto/grpc_gcp/handshaker_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/internal/proto/grpc_gcp/transport_security_common.pb.go | safe | This is standard protoc-gen-go generated code for gRPC ALTS transport security protobuf definitions with no malicious patterns detected. |
| credentials/alts/internal/testutil/testutil.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/alts/utils.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/credentials.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/google/gcp_service_account_identity_credentials.go | safe | The code implements standard GCP service account ID token credentials using Google's auth library and metadata server; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or unauthorized file access were detected. |
| credentials/google/google.go | safe | This is the standard gRPC-Go Google credentials implementation, which uses well-known authentication mechanisms (ADC, ALTS, TLS) without any malicious patterns. |
| credentials/google/internal/internal.go | safe | No malicious patterns detected; the file only declares internal package variables and function pointers for credential handling without any suspicious behavior. |
| credentials/google/xds.go | safe | No malicious patterns detected; code is a legitimate gRPC transport credentials implementation for Google Cloud xDS with standard TLS/ALTS selection logic. |
| credentials/insecure/insecure.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/jwt/doc.go | safe | No malicious patterns detected; this is a standard package documentation file for gRPC JWT credentials with no executable code. |
| credentials/jwt/file_reader.go | safe | No malicious patterns detected; the code is a legitimate JWT file reader that only parses tokens and checks expiration without any suspicious behavior. |
| credentials/jwt/token_file_call_creds.go | safe | No malicious patterns detected; the code is a legitimate gRPC JWT token file credentials implementation with standard token caching, backoff, and file reading logic. |
| credentials/local/local.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/oauth/oauth.go | safe | No malicious patterns detected; this is the official gRPC OAuth credentials implementation with expected behavior and no exfiltration, obfuscation, or backdoor code. |
| credentials/sts/sts.go | safe | No malicious patterns detected in the STS credentials implementation; code is a legitimate gRPC library token exchange mechanism. |
| credentials/tls.go | safe | No malicious patterns detected; this is the standard gRPC-Go TLS credentials implementation with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| credentials/tls/certprovider/distributor.go | safe | Cleared by Jev triage; no further analysis needed |
| credentials/tls/certprovider/pemfile/builder.go | safe | No malicious patterns detected |
| credentials/tls/certprovider/pemfile/watcher.go | safe | No malicious patterns detected; the code is a legitimate gRPC certificate provider plugin for watching PEM files. |
| credentials/tls/certprovider/provider.go | safe | No malicious patterns detected |
| credentials/tls/certprovider/store.go | safe | No malicious patterns detected |
| credentials/xds/xds.go | safe | No malicious patterns detected; the code is a legitimate gRPC xDS credentials implementation with standard TLS handshaking and no suspicious behaviors. |
| dialoptions.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | No malicious patterns detected |
| encoding/encoding.go | safe | No malicious patterns detected in this standard gRPC encoding registration package. |
| encoding/encoding_v2.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/gzip/gzip.go | safe | No malicious patterns detected; the code implements a standard gRPC gzip compressor with no exfiltration, credential harvesting, obfuscation, or other red flags. |
| encoding/internal/internal.go | safe | No malicious patterns detected; the file only declares a testing variable and contains no executable code or suspicious behavior. |
| encoding/proto/proto.go | safe | No malicious patterns detected in the gRPC proto codec implementation; the code performs standard protobuf marshaling/unmarshaling registration and contains no exfiltration, credential harvesting, obfuscation, or process execution. |
| experimental/balancer/hostname/hostname.go | safe | Cleared by Jev triage; no further analysis needed |
| experimental/balancer/weight/weight.go | safe | Cleared by Jev triage; no further analysis needed |
| experimental/credentials/internal/spiffe.go | safe | Cleared by Jev triage; no further analysis needed |
| experimental/credentials/internal/syscallconn.go | safe | No malicious patterns detected; the code is a straightforward syscall.Conn wrapper with no network, filesystem, process, or dynamic execution behavior. |
| experimental/experimental.go | safe | No malicious patterns detected; the file only exposes experimental gRPC buffer pool and compressor configuration APIs via internal function indirection. |
| experimental/opentelemetry/trace_options.go | safe | Cleared by Jev triage; no further analysis needed |
| experimental/stats/metricregistry.go | safe | The file is a legitimate gRPC metrics registry implementation with no malicious patterns detected. |
| experimental/stats/metrics.go | safe | Cleared by Jev triage; no further analysis needed |
| experimental/stats/telemetry/labels.go | safe | No malicious patterns detected |
| grpclog/component.go | safe | Cleared by Jev triage; no further analysis needed |
| grpclog/glogger/glogger.go | safe | This is the legitimate gRPC-Go glog logger adapter; it only wires glog into grpclog via init() and contains no malicious patterns. |
| grpclog/grpclog.go | safe | This is the standard gRPC Go logging package; no malicious patterns, exfiltration, or backdoors detected. |
| grpclog/internal/grpclog.go | safe | Cleared by Jev triage; no further analysis needed |
| grpclog/internal/logger.go | safe | Cleared by Jev triage; no further analysis needed |
| grpclog/internal/loggerv2.go | safe | Cleared by Jev triage; no further analysis needed |
| grpclog/logger.go | safe | No malicious patterns detected in the grpclog/logger.go file; it is a standard gRPC logging interface wrapper with no suspicious behavior. |
| grpclog/loggerv2.go | safe | No malicious patterns detected; this is a legitimate gRPC logging configuration file that reads standard log level environment variables and writes to stderr or discard, with no network, exec, or exfiltration behavior. |
| health/client.go | safe | No malicious patterns detected |
| health/grpc_health_v1/health.pb.go | safe | No malicious patterns detected in this standard gRPC health check protobuf-generated Go file. |
| health/grpc_health_v1/health_grpc.pb.go | safe | No malicious patterns detected |
| health/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| health/producer.go | safe | No malicious patterns detected; the code is a legitimate gRPC health checking producer with standard Go patterns and no suspicious behavior. |
| health/server.go | safe | Cleared by Jev triage; no further analysis needed |
| interceptor.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/admin/admin.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/backoff/backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancer/gracefulswitch/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancer/gracefulswitch/gracefulswitch.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancer/nop/nop.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancer/stub/stub.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancergroup/balancergroup.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancergroup/balancerstateaggregator.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/balancerload/load.go | safe | No malicious patterns detected |
| internal/binarylog/binarylog_testutil.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/binarylog/env_config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/binarylog/method_logger.go | safe | No malicious patterns detected |
| internal/binarylog/sink.go | safe | No malicious patterns detected; the file is a legitimate gRPC binary logging sink implementation with no exfiltration, credential harvesting, obfuscation, or shell execution. |
| internal/buffer/unbounded.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cache/timeoutCache.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/channel.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/channelmap.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/funcs.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/server.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/socket.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/subchannel.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/syscall_linux.go | safe | No malicious patterns detected; the code only reads socket options from a provided connection using standard syscall interfaces for legitimate channelz monitoring purposes. |
| internal/channelz/syscall_nonlinux.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/channelz/trace.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/credentials/credentials.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/credentials/spiffe.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/credentials/spiffe/spiffe.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/credentials/syscallconn.go | safe | No malicious patterns detected |
| internal/credentials/util.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/credentials/xds/handshake_info.go | safe | The code is a legitimate gRPC xDS credentials implementation with no malicious exfiltration, credential harvesting, obfuscation, backdoor, or arbitrary code execution patterns; only standard security-sensitive TLS custom verification logic is present. |
| internal/envconfig/envconfig.go | safe | Legitimate gRPC environment configuration code with no malicious patterns detected. |
| internal/envconfig/observability.go | safe | No malicious patterns detected |
| internal/envconfig/xds.go | safe | No malicious patterns detected; the file only reads environment variables for gRPC xDS configuration with standard, documented feature flags. |
| internal/experimental.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/googlecloud/googlecloud.go | safe | No malicious patterns detected |
| internal/googlecloud/manufacturer.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/googlecloud/manufacturer_linux.go | safe | No malicious patterns detected |
| internal/googlecloud/manufacturer_windows.go | safe | No malicious patterns detected; the code only queries the Windows BIOS manufacturer via PowerShell for legitimate platform identification in gRPC. |
| internal/grpclog/prefix_logger.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcsync/callback_serializer.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcsync/event.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcsync/pubsub.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcsync/refcounted.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpctest/grpctest.go | safe | No malicious patterns detected |
| internal/grpctest/tlogger.go | safe | No malicious patterns detected |
| internal/grpcutil/compressor.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcutil/encode_duration.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcutil/grpcutil.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcutil/metadata.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/grpcutil/method.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/hierarchy/hierarchy.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/idle/idle.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/internal.go | safe | No malicious patterns detected |
| internal/leakcheck/leakcheck.go | safe | This is a legitimate gRPC leak-checking test utility that tracks goroutines, buffers, timers, and async reporters for testing purposes; no malicious patterns detected. |
| internal/leakcheck/leakcheck_enabled.go | safe | No malicious patterns detected; the file is a benign gRPC test helper that enables buffer leak checking under a build tag. |
| internal/mem/buffer_pool.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/metadata/metadata.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/optional/optional.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pretty/pretty.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/profiling/buffer/buffer.go | safe | No malicious patterns detected; the code implements a lock-free circular buffer for gRPC profiling with no external data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| internal/profiling/goid_modified.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/profiling/goid_regular.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/profiling/profiling.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/proto/grpc_lookup_v1/rls.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for gRPC Route Lookup Service protobuf definitions. |
| internal/proto/grpc_lookup_v1/rls_config.pb.go | safe | This is standard auto-generated protobuf Go code from the official gRPC library with no malicious patterns; all operations are limited to descriptor registration and static data handling. |
| internal/proto/grpc_lookup_v1/rls_grpc.pb.go | safe | This is standard generated gRPC Go code for a route lookup service with no malicious patterns detected. |
| internal/proxyattributes/proxyattributes.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/resolver/config_selector.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/resolver/delegatingresolver/delegatingresolver.go | safe | No malicious patterns detected; the file is a legitimate gRPC Go resolver implementation handling proxy URL resolution with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| internal/resolver/dns/dns_resolver.go | safe | No malicious patterns detected |
| internal/resolver/dns/internal/internal.go | safe | This is a legitimate gRPC DNS resolver internal utility file with standard interfaces and overridable test hooks; no malicious patterns detected. |
| internal/resolver/passthrough/passthrough.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/resolver/unix/unix.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/ringhash/ringhash.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/serviceconfig/duration.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/serviceconfig/serviceconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/stats/labels.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/stats/metrics_recorder_list.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/stats/stats.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/status/status.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/stubserver/stubserver.go | safe | No malicious patterns detected; this is a legitimate gRPC test stub server implementation. |
| internal/syscall/syscall_linux.go | safe | No malicious patterns detected; the code is a legitimate gRPC syscall utility for CPU/rusage stats and TCP user timeout manipulation. |
| internal/syscall/syscall_nonlinux.go | safe | No malicious patterns detected; the code is a legitimate gRPC platform-specific stub for non-Linux systems. |
| internal/tcp_keepalive_others.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/tcp_keepalive_unix.go | safe | No malicious patterns detected; this is a legitimate gRPC utility that configures OS-default TCP keepalive settings on Unix dialers. |
| internal/tcp_keepalive_windows.go | safe | No malicious patterns detected |
| internal/testutils/balancer.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/blocking_context_dialer.go | safe | No malicious patterns detected; this is a legitimate gRPC test utility for blocking dialer operations. |
| internal/testutils/channel.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/envconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/fakegrpclb/server.go | safe | This is a test utility implementing a fake gRPC load balancer server with no malicious patterns, external data exfiltration, or suspicious behavior detected. |
| internal/testutils/http_client.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/local_listener.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/marshal_any.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/parse_port.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/parse_url.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/pickfirst/pickfirst.go | safe | No malicious patterns detected; the file is a standard gRPC test helper for verifying pick_first load balancing behavior with no network exfiltration, credential harvesting, obfuscation, or command execution. |
| internal/testutils/pipe_listener.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/proxyserver/proxyserver.go | safe | No malicious patterns detected; this is a standard gRPC test proxy server implementation with no data exfiltration, credential harvesting, or backdoor behavior. |
| internal/testutils/resolver.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/restartable_listener.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/rls/fake_rls_server.go | safe | The code is a test utility implementing a fake gRPC RouteLookupService server with no malicious patterns detected. |
| internal/testutils/roundrobin/roundrobin.go | safe | No malicious patterns detected; this is a legitimate gRPC test utility for verifying round-robin load balancing behavior. |
| internal/testutils/state.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/stats/test_metrics_recorder.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/status_equal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/stubstatshandler.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/tls_creds.go | safe | This is a legitimate gRPC test utility file that loads TLS test certificates from the testdata directory for unit testing; no malicious patterns detected. |
| internal/testutils/wrappers.go | safe | No malicious patterns detected |
| internal/testutils/wrr.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/xds/e2e/bootstrap.go | safe | The file contains only test utilities for generating xDS bootstrap configurations and copying test certificates; no malicious patterns or security concerns were found. |
| internal/testutils/xds/e2e/clientresources.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/xds/e2e/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testutils/xds/e2e/server.go | safe | This is a legitimate gRPC xDS test utility for end-to-end testing; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or suspicious network/file/process activity were detected. |
| internal/testutils/xds/e2e/setup/setup.go | safe | No malicious patterns detected; the code only sets up xDS test management servers and resolvers within test scopes. |
| internal/testutils/xds/fakeserver/server.go | safe | No malicious patterns detected; this is a test utility implementing a fake gRPC xDS/LRS server with no external network, file system, credential, or command execution behavior. |
| internal/testutils/xds_bootstrap.go | safe | This is a legitimate test utility that creates temporary bootstrap files for testing purposes with proper cleanup, and does not contain any malicious patterns. |
| internal/transport/bdp_estimator.go | safe | No malicious patterns detected |
| internal/transport/client_stream.go | safe | The code is a standard gRPC client stream implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution. |
| internal/transport/controlbuf.go | safe | No malicious patterns detected; this is legitimate gRPC-Go control buffer and loopy writer implementation code. |
| internal/transport/defaults.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/flowcontrol.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/handler_server.go | safe | No malicious patterns detected; this is a legitimate gRPC server transport implementation from the official gRPC-Go library. |
| internal/transport/http2_client.go | safe | This is the legitimate gRPC-Go HTTP/2 client transport implementation; no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, backdoors, or suspicious process spawning were detected. |
| internal/transport/http2_server.go | safe | No malicious patterns detected; the code is the legitimate gRPC-go HTTP/2 server transport implementation with standard networking, flow control, and keepalive logic. |
| internal/transport/http_util.go | safe | No malicious patterns detected; this is a legitimate gRPC transport HTTP/2 utility file from the official google.golang.org/grpc package. |
| internal/transport/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/networktype/networktype.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/proxy.go | safe | No malicious patterns detected; the code is a standard gRPC HTTP CONNECT proxy implementation with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| internal/transport/readyreader/raw_conn_linux.go | safe | No malicious patterns detected; the file contains only platform-specific syscall wrappers for non-blocking reads with no external communication, credential access, or code execution. |
| internal/transport/readyreader/raw_conn_nonlinux.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/transport/readyreader/ready_reader.go | safe | No malicious patterns detected; the code is a legitimate gRPC transport utility for non-blocking socket reads with proper buffer pool management. |
| internal/transport/server_stream.go | safe | No malicious patterns detected; this is legitimate gRPC server stream transport code from the official google.golang.org/grpc package. |
| internal/transport/transport.go | safe | This is standard gRPC transport code from the official google.golang.org/grpc repository with no malicious patterns detected. |
| internal/wrr/edf.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/wrr/random.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/wrr/wrr.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/balancer.go | safe | No malicious patterns detected; the file only registers gRPC xDS balancers via standard blank imports. |
| internal/xds/balancer/cdsbalancer/cdsbalancer.go | safe | No malicious patterns detected; this is a legitimate gRPC xDS CDS balancer implementation with standard init registration, JSON config parsing, and no exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| internal/xds/balancer/cdsbalancer/configbuilder.go | safe | No malicious patterns detected; this is benign gRPC xDS CDS balancer configuration code with no data exfiltration, credential harvesting, obfuscation, network calls, or process execution. |
| internal/xds/balancer/cdsbalancer/configbuilder_childname.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/cdsbalancer/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clusterimpl/clusterimpl.go | safe | This is a legitimate gRPC xDS cluster implementation balancer with no malicious patterns; all network, credential, and provider operations are part of its intended xDS load-balancing functionality. |
| internal/xds/balancer/clusterimpl/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clusterimpl/internal/internal.go | safe | No malicious patterns detected; the file only aliases crypto/x509.SystemCertPool for test overriding and contains no executable, network, or credential-related logic. |
| internal/xds/balancer/clusterimpl/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clusterimpl/picker.go | safe | This is a legitimate gRPC-Go internal load balancing picker implementation with no malicious patterns detected. |
| internal/xds/balancer/clustermanager/balancerstateaggregator.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clustermanager/clustermanager.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clustermanager/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/clustermanager/picker.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/loadstore/load_store_wrapper.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/outlierdetection/balancer.go | safe | The code is a legitimate gRPC outlier detection load balancing implementation with no malicious patterns, external data exfiltration, or suspicious behavior. |
| internal/xds/balancer/outlierdetection/callcounter.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/outlierdetection/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/outlierdetection/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/outlierdetection/subconn_wrapper.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/priority/balancer.go | safe | No malicious patterns detected; this is a standard gRPC priority balancer implementation with no data exfiltration, credential harvesting, or dynamic code execution. |
| internal/xds/balancer/priority/balancer_child.go | safe | No malicious patterns detected in the gRPC priority balancer child implementation; all code is legitimate load balancing logic with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| internal/xds/balancer/priority/balancer_priority.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/priority/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/priority/ignore_resolve_now.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/priority/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/wrrlocality/balancer.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/balancer/wrrlocality/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/bootstrap/bootstrap.go | safe | This is legitimate gRPC-Go xDS bootstrap parsing code from the official grpc-go library with no malicious patterns detected. |
| internal/xds/bootstrap/jwtcreds/call_creds.go | safe | No malicious patterns detected; the code is a straightforward JWT call credentials configuration parser with no exfiltration, obfuscation, or suspicious behavior. |
| internal/xds/bootstrap/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/bootstrap/template.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/grpctransport/grpc_transport.go | safe | No malicious patterns detected; the code is a standard gRPC transport builder implementation with proper connection pooling and cleanup, using only the grpc library's public APIs. |
| internal/xds/clients/internal/backoff/backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/buffer/unbounded.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/pretty/pretty.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/syncutil/callback_serializer.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/syncutil/event.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/channel.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/e2e/clientresources.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/e2e/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/e2e/server.go | safe | No malicious patterns detected |
| internal/xds/clients/internal/testutils/fakeserver/server.go | safe | No malicious patterns detected; this is a legitimate gRPC test utility implementing a fake xDS/LRS management server locally. |
| internal/xds/clients/internal/testutils/faketransport/xds_fake_transport.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/marshal_any.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/restartable_listener.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/internal/testutils/wrappers.go | safe | No malicious patterns detected; this is a benign Go test utility for wrapping net.Conn and net.Listener with channel notifications. |
| internal/xds/clients/lrsclient/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/lrsclient/load_store.go | safe | This is a legitimate gRPC xDS LRS load store implementation with only standard library usage; no malicious patterns detected. |
| internal/xds/clients/lrsclient/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/lrsclient/lrs_stream.go | safe | The code is part of the gRPC-Go library and implements an LRS (Load Reporting Service) client stream; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or backdoor installation. |
| internal/xds/clients/lrsclient/lrsclient.go | safe | No malicious patterns detected |
| internal/xds/clients/lrsclient/lrsconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/transport_builder.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/ads_stream.go | safe | No malicious patterns detected; this is a legitimate gRPC xDS ADS stream client implementation from the gRPC-Go project. |
| internal/xds/clients/xdsclient/authority.go | safe | No malicious patterns detected in the xDS authority implementation; it is standard gRPC xDS client logic with proper synchronization and no external data exfiltration or code execution. |
| internal/xds/clients/xdsclient/channel.go | safe | No malicious patterns detected |
| internal/xds/clients/xdsclient/clientimpl_watchers.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/xdsresource/ads_stream.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/xdsresource/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/xdsresource/name.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/xdsresource/type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/internal/xdsresource/version.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/metrics/metrics.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/resource_watcher.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clients/xdsclient/xdsclient.go | safe | No malicious patterns detected |
| internal/xds/clients/xdsclient/xdsconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clusterspecifier/cluster_specifier.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/clusterspecifier/rls/rls.go | safe | No malicious patterns detected; the code is a legitimate gRPC cluster specifier plugin implementation from the official grpc-go repository. |
| internal/xds/httpfilter/ext_authz/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/httpfilter/ext_authz/ext_authz.go | safe | No malicious patterns detected; the file is a legitimate gRPC xDS External Authorization HTTP filter implementation with no data exfiltration, code execution, credential harvesting, or other suspicious behavior. |
| internal/xds/httpfilter/extconfig.go | safe | No malicious patterns detected |
| internal/xds/httpfilter/extproc/config.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/httpfilter/extproc/ext_proc.go | safe | No malicious patterns detected |
| internal/xds/httpfilter/extproc/internal/internal.go | safe | No malicious patterns detected |
| internal/xds/httpfilter/extproc/metrics.go | safe | No malicious patterns detected; the code only registers observability metrics for gRPC ext_proc filter durations. |
| internal/xds/httpfilter/fault/fault.go | safe | No malicious patterns detected; the code implements the standard gRPC Envoy Fault Injection HTTP filter with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go | safe | No malicious patterns detected; this is a legitimate gRPC xDS GCP Authentication HTTP filter implementation with standard credential handling via google.NewServiceAccountIdentityCredentials and no suspicious network, filesystem, or process operations. |
| internal/xds/httpfilter/httpfilter.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/httpfilter/rbac/rbac.go | safe | No malicious patterns detected |
| internal/xds/httpfilter/router/router.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/matcher/matcher_header.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/rbac/converter.go | safe | No malicious patterns detected; the code is a legitimate gRPC-Go xDS RBAC audit logger configuration converter with no network, filesystem, credential, or dynamic execution risks. |
| internal/xds/rbac/matchers.go | safe | No malicious patterns detected; this is legitimate gRPC RBAC matcher code implementing permission and principal matching for xDS-based access control. |
| internal/xds/rbac/rbac_engine.go | safe | No malicious patterns detected; the code implements standard RBAC authorization logic for gRPC without exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| internal/xds/resolver/internal/internal.go | safe | No malicious patterns detected; the file only declares two unexported variables for testing overrides with no executable code. |
| internal/xds/resolver/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/resolver/serviceconfig.go | safe | No malicious patterns detected; this is a legitimate gRPC xDS resolver service config implementation. |
| internal/xds/resolver/xds_resolver.go | safe | No malicious patterns detected; this is standard gRPC-Go xDS resolver code with proper resource management and no data exfiltration, credential harvesting, or backdoor behavior. |
| internal/xds/server/conn_wrapper.go | safe | No malicious patterns detected |
| internal/xds/server/filter_chain_manager.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/server/listener_wrapper.go | safe | No malicious patterns detected |
| internal/xds/server/rds_handler.go | safe | No malicious patterns detected; the code is a legitimate gRPC xDS RDS handler with normal watch/cancel logic and no data exfiltration, credential harvesting, obfuscation, command execution, or suspicious network/file system activity. |
| internal/xds/server/routing.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/testutils/fakeclient/client.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/testutils/resource_watcher.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/testutils/testutils.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/attributes.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/client.go | safe | No malicious patterns detected; this is a standard gRPC xDS client interface definition with no data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| internal/xds/xdsclient/clientimpl.go | safe | This is legitimate gRPC xDS client code with no malicious patterns detected; it performs standard configuration building, metrics reporting, and connection management without exfiltration, credential harvesting, or dynamic code execution. |
| internal/xds/xdsclient/clientimpl_loadreport.go | safe | The code implements legitimate gRPC xDS load reporting functionality with no malicious patterns detected. |
| internal/xds/xdsclient/internal/internal.go | safe | No malicious patterns detected |
| internal/xds/xdsclient/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/pool.go | safe | This is a legitimate gRPC-Go xDS client pool implementation with no malicious patterns; standard library usage is benign and consistent with its documented purpose. |
| internal/xds/xdsclient/requests_counter.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/resource_types.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdslbregistry/converter/converter.go | safe | No malicious patterns detected; the code is a legitimate gRPC xDS load balancing converter with no network, filesystem, process execution, credential harvesting, or obfuscation concerns. |
| internal/xds/xdsclient/xdslbregistry/xdslbregistry.go | safe | No malicious patterns detected; the code is a benign xDS load balancing registry with no network, filesystem, process, or obfuscation concerns. |
| internal/xds/xdsclient/xdsresource/cluster_resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/endpoints_resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/filter_chain.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/grpc_service.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/listener_resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/logging.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/matcher.go | safe | This is a legitimate gRPC xDS route matcher implementing path, header, fraction, and virtual host matching with no malicious patterns detected. |
| internal/xds/xdsclient/xdsresource/matcher_path.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/metadata.go | safe | No malicious patterns detected; the code is a legitimate part of gRPC's xDS client that registers metadata converters and parses proxy address and audience metadata. |
| internal/xds/xdsclient/xdsresource/name.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/route_config_resource_type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/type.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/type_cds.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/type_eds.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/type_lds.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/type_rds.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/unmarshal_cds.go | safe | No malicious patterns detected; this is legitimate gRPC xDS CDS resource unmarshaling and validation code. |
| internal/xds/xdsclient/xdsresource/unmarshal_eds.go | safe | No malicious patterns detected |
| internal/xds/xdsclient/xdsresource/unmarshal_lds.go | safe | No malicious patterns detected; the code is a legitimate gRPC xDS resource unmarshaling implementation that performs validation and parsing of Envoy configuration protos without any exfiltration, credential harvesting, obfuscation, or shell execution. |
| internal/xds/xdsclient/xdsresource/unmarshal_rds.go | safe | No malicious patterns detected; this is legitimate gRPC xDS route configuration unmarshaling logic. |
| internal/xds/xdsclient/xdsresource/version/version.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsclient/xdsresource/xdsconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/xds/xdsdepmgr/xds_dependency_manager.go | safe | This is a legitimate gRPC xDS dependency manager with no malicious patterns detected. |
| interop/alts/client/client.go | safe | No malicious patterns detected |
| interop/alts/server/server.go | safe | No malicious patterns detected |
| interop/client/client.go | safe | No malicious patterns detected |
| interop/fake_grpclb/fake_grpclb.go | safe | No malicious patterns detected; the file is a test utility for running a fake gRPC load balancer server with command-line flags and no exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| interop/grpc_testing/benchmark_service.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated gRPC service descriptor file with no network, filesystem, credential, or process execution activity beyond typical init-time proto registration. |
| interop/grpc_testing/benchmark_service_grpc.pb.go | safe | No malicious patterns detected; this is a standard gRPC-generated service stub file for testing purposes. |
| interop/grpc_testing/control.pb.go | safe | This is a standard protobuf-generated Go file for gRPC testing control messages with no malicious patterns detected. |
| interop/grpc_testing/core/stats.pb.go | safe | No malicious patterns detected in this auto-generated protobuf Go file. |
| interop/grpc_testing/empty.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file from gRPC's testing package with only benign initialization and reflection code. |
| interop/grpc_testing/messages.pb.go | safe | This is standard protoc-gen-go generated code for gRPC testing message definitions with no malicious patterns, network calls, dynamic execution, or environment/credential access. |
| interop/grpc_testing/payloads.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code with only benign init() registration and no network, filesystem, process, or obfuscated behavior. |
| interop/grpc_testing/report_qps_scenario_service.pb.go | safe | No malicious patterns detected |
| interop/grpc_testing/report_qps_scenario_service_grpc.pb.go | safe | No malicious patterns detected |
| interop/grpc_testing/stats.pb.go | safe | No malicious patterns detected; this is standard protobuf-generated Go code from the gRPC project with no exfiltration, execution, or filesystem/network abuse. |
| interop/grpc_testing/test.pb.go | safe | Standard protoc-gen-go generated code with no malicious patterns, network calls, credential harvesting, or code execution. |
| interop/grpc_testing/test_grpc.pb.go | safe | This is standard protoc-generated gRPC service stub code with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| interop/grpc_testing/worker_service.pb.go | safe | No malicious patterns detected in this protoc-generated Go gRPC service stub. |
| interop/grpc_testing/worker_service_grpc.pb.go | safe | No malicious patterns detected in this auto-generated gRPC service definition file. |
| interop/http2/negative_http2_client.go | safe | This is a legitimate gRPC interop test client for negative HTTP/2 test cases with no malicious patterns detected. |
| interop/orcalb.go | safe | No malicious patterns detected; the code is a legitimate gRPC interop test load balancer implementing ORCA metrics collection. |
| interop/server/server.go | safe | No malicious patterns detected; this is a standard gRPC interop test server implementation from the official gRPC-Go repository. |
| interop/soak_tests.go | safe | No malicious patterns detected; this is a standard gRPC soak test implementation with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| interop/stress/client/main.go | safe | No malicious patterns detected; this is a legitimate gRPC interop stress test client with expected networking behavior only. |
| interop/stress/grpc_testing/metrics.pb.go | safe | This is a standard protoc-gen-go generated file for gRPC testing metrics with no malicious patterns detected. |
| interop/stress/grpc_testing/metrics_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| interop/stress/metrics_client/main.go | safe | No malicious patterns detected; the code is a straightforward gRPC metrics client with only a minor low-severity use of insecure transport credentials. |
| interop/xds_federation/client.go | safe | This is a legitimate gRPC interop test client from the official google.golang.org/grpc repository with no malicious patterns detected. |
| keepalive/keepalive.go | safe | Cleared by Jev triage; no further analysis needed |
| mem/buffer_slice.go | safe | Cleared by Jev triage; no further analysis needed |
| mem/buffers.go | safe | Cleared by Jev triage; no further analysis needed |
| metadata/metadata.go | safe | Cleared by Jev triage; no further analysis needed |
| orca/call_metrics.go | safe | No malicious patterns detected; the code is a legitimate gRPC ORCA per-RPC metrics recorder implementation using standard library and gRPC packages. |
| orca/internal/internal.go | safe | Cleared by Jev triage; no further analysis needed |
| orca/orca.go | safe | This is an official-looking gRPC ORCA package that performs localized metadata parsing and registration only, with no malicious patterns detected. |
| orca/producer.go | safe | No malicious patterns detected; the code is a standard gRPC ORCA load reporting client with no exfiltration, credential harvesting, obfuscation, or backdoor logic. |
| orca/server_metrics.go | safe | Cleared by Jev triage; no further analysis needed |
| orca/service.go | safe | No malicious patterns detected; this is a legitimate gRPC ORCA service implementation with no data exfiltration, credential harvesting, shell commands, or obfuscated code. |
| peer/peer.go | safe | Cleared by Jev triage; no further analysis needed |
| picker_wrapper.go | safe | Cleared by Jev triage; no further analysis needed |
| preloader.go | safe | Cleared by Jev triage; no further analysis needed |
| profiling/cmd/catapult.go | safe | No malicious patterns detected; the code is a legitimate gRPC profiling utility that converts stats to Catapult JSON format. |
| profiling/cmd/flags.go | safe | Cleared by Jev triage; no further analysis needed |
| profiling/cmd/main.go | safe | No malicious patterns detected |
| profiling/profiling.go | safe | Cleared by Jev triage; no further analysis needed |
| profiling/proto/service.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for gRPC profiling definitions with no executable, network, filesystem, or credential-harvesting behavior. |
| profiling/proto/service_grpc.pb.go | safe | This is standard auto-generated gRPC Go client/server code for a Profiling service with no malicious patterns, executable side effects, or suspicious imports. |
| reflection/adapt.go | safe | Cleared by Jev triage; no further analysis needed |
| reflection/grpc_reflection_v1/reflection.pb.go | safe | This is a standard protoc-gen-go generated file for gRPC reflection protocol messages containing only message definitions, getters, and protobuf runtime registration code with no malicious patterns. |
| reflection/grpc_reflection_v1/reflection_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| reflection/grpc_reflection_v1alpha/reflection.pb.go | safe | This is a standard gRPC reflection protobuf-generated Go file containing only message definitions, getters, and descriptor initialization with no malicious patterns. |
| reflection/grpc_reflection_v1alpha/reflection_grpc.pb.go | safe | No malicious patterns detected in this generated gRPC reflection service code; it contains only standard gRPC client/server stubs and registration logic. |
| reflection/grpc_testing/proto2.pb.go | safe | No malicious patterns detected |
| reflection/grpc_testing/proto2_ext.pb.go | safe | This is a standard protoc-gen-go generated file for gRPC reflection testing with no malicious patterns detected. |
| reflection/grpc_testing/proto2_ext2.pb.go | safe | This is a standard protoc-gen-go generated file for gRPC testing protocols with no malicious patterns, no network/file/exec operations, and only routine proto initialization code. |
| reflection/grpc_testing/test.pb.go | safe | No malicious patterns detected |
| reflection/grpc_testing/test_grpc.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| reflection/internal/internal.go | safe | No malicious patterns detected; the code implements gRPC reflection service handling without any exfiltration, credential harvesting, obfuscation, mining, backdoors, or suspicious system interactions. |
| reflection/serverreflection.go | safe | No malicious patterns detected; this is the standard gRPC server reflection implementation with no data exfiltration, credential harvesting, obfuscation, network calls, or process execution. |
| resolver/dns/dns_resolver.go | safe | No malicious patterns detected |
| resolver/manual/manual.go | safe | Cleared by Jev triage; no further analysis needed |
| resolver/map.go | safe | Cleared by Jev triage; no further analysis needed |
| resolver/passthrough/passthrough.go | safe | This is a legitimate deprecated gRPC passthrough resolver package that only performs a side-effect import with no malicious patterns. |
| resolver/resolver.go | safe | Cleared by Jev triage; no further analysis needed |
| resolver/ringhash/attr.go | safe | Cleared by Jev triage; no further analysis needed |
| resolver_wrapper.go | safe | No malicious patterns detected; this is standard gRPC resolver wrapper code with proper synchronization and no external I/O, credential access, or dynamic execution. |
| rpc_util.go | safe | This is legitimate grpc-go library code containing standard RPC utility functions, compression/decompression, and CallOptions with no malicious patterns detected. |
| server.go | safe | No malicious patterns detected; this is the standard gRPC-Go server implementation with legitimate networking, reflection, and context handling. |
| service_config.go | safe | This is the standard gRPC-Go service config parser; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process/network activity. |
| serviceconfig/serviceconfig.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/handlers.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/metrics.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/client_metrics.go | safe | No malicious patterns detected |
| stats/opentelemetry/client_tracing.go | safe | No malicious patterns detected; the file contains standard gRPC OpenTelemetry client tracing instrumentation code with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| stats/opentelemetry/csm/observability.go | safe | No malicious patterns detected; the code is a legitimate CSM OpenTelemetry integration for gRPC that conditionally enables observability based on target URL. |
| stats/opentelemetry/csm/pluginoption.go | safe | The code is a legitimate gRPC OpenTelemetry CSM plugin that reads OpenTelemetry resource attributes and CSM environment variables to generate observability labels; it contains no malicious patterns, exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| stats/opentelemetry/grpc_trace_bin_propagator.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/internal/pluginoption.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/internal/testutils/testutils.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/internal/tracing/carrier.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/opentelemetry.go | safe | No malicious patterns detected in the provided gRPC OpenTelemetry instrumentation code; it is a legitimate metrics/tracing plugin without exfiltration, credential harvesting, obfuscation, or code execution risks. |
| stats/opentelemetry/server_metrics.go | safe | No malicious patterns detected |
| stats/opentelemetry/server_tracing.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/opentelemetry/trace.go | safe | Cleared by Jev triage; no further analysis needed |
| stats/stats.go | safe | No malicious patterns detected |
| status/status.go | safe | Cleared by Jev triage; no further analysis needed |
| stream.go | safe | This is standard gRPC-Go client/server stream implementation code with no malicious patterns detected. |
| stream_interfaces.go | safe | Cleared by Jev triage; no further analysis needed |
| tap/tap.go | safe | Cleared by Jev triage; no further analysis needed |
| testdata/grpc_testing_not_regenerated/dynamic.go | safe | No malicious patterns detected; the file contains only a static Protocol Buffer descriptor byte slice for gRPC testing. |
| testdata/grpc_testing_not_regenerated/simple_message_v1.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code with only benign init() registrations and a static gzipped file descriptor. |
| testdata/grpc_testing_not_regenerated/testv3.go | safe | No malicious patterns detected; the file is standard generated gRPC/protobuf code with no exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| testdata/testdata.go | safe | No malicious patterns detected |
| trace.go | safe | Cleared by Jev triage; no further analysis needed |
| trace_notrace.go | safe | Cleared by Jev triage; no further analysis needed |
| trace_withtrace.go | safe | Cleared by Jev triage; no further analysis needed |
| version.go | safe | Cleared by Jev triage; no further analysis needed |
| xds/bootstrap/bootstrap.go | safe | Cleared by Jev triage; no further analysis needed |
| xds/bootstrap/credentials.go | safe | No malicious patterns detected; the file contains standard gRPC credential builder registrations with no exfiltration, obfuscation, or suspicious behavior. |
| xds/csds/csds.go | safe | No malicious patterns detected |
| xds/googledirectpath/utils.go | safe | No malicious patterns detected; the code performs expected metadata server requests for gRPC Google Direct Path configuration. |
| xds/server.go | safe | No malicious patterns detected in the xDS server implementation; it is standard gRPC library code from the official google.golang.org/grpc module. |
| xds/server_options.go | safe | Cleared by Jev triage; no further analysis needed |
| xds/xds.go | safe | No malicious patterns detected; this is legitimate gRPC xDS package code with standard plugin registration and an admin service init function. |
Frequently asked questions
Is google.golang.org/grpc safe to use?
No confirmed malware was found in google.golang.org/grpc@v1.84.0, but the review flagged 16 medium, 41 low severity findings for risky patterns worth checking before you rely on it.
Does google.golang.org/grpc contain malware?
No malware was identified in google.golang.org/grpc@v1.84.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was google.golang.org/grpc checked?
Togoder Security downloaded the published Go package and had an AI model read its 545 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan google.golang.org/grpc together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in google.golang.org/grpc@v1.84.0, cost nothing.