# google.golang.org/protobuf@v1.36.12 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:20.000Z
- Files reviewed: 336
- Findings: 4 medium, 18 low severity findings
- Report: https://security.togoder.click/go/google.golang.org/protobuf
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package google.golang.org/protobuf@v1.36.12 on Oct 5, 2026. An AI review of 336 source files produced 4 medium, 18 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsafe pointer manipulation

Finding ID: `NPS-F5E18207575B`

File: `internal/impl/api_export_opaque.go:68`

Extensive use of unsafe.Pointer and type punning to convert interfaces to raw pointers and directly manipulate memory (interfaceToPointer, atomicGetPointer, AtomicLoadPointer, AtomicInitializePointer, AtomicSetPointer). While these are legitimate low-level operations for the protobuf runtime, they bypass Go's type safety and could be misused.

### [medium] Raw memory writes via unsafe pointers

Finding ID: `NPS-7CFF55E259F0`

File: `internal/impl/api_export_opaque.go:100`

AtomicLoadPointer and AtomicInitializePointer write directly through unsafe pointers passed in as parameters without bounds or validity verification, which is inherently dangerous if callers pass invalid addresses.

### [medium] Unsafe pointer arithmetic

Finding ID: `NPS-AC1F947B3F84`

File: `internal/impl/presence.go:25`

The code uses extensive unsafe.Pointer arithmetic to access memory within a protobuf presence bitmap. While this is likely part of the official Go protobuf library (as indicated by the copyright notice and package name), such low-level memory manipulation can lead to memory corruption, out-of-bounds reads/writes, or crashes if the provided indices or sizes are incorrect. This is a potential security concern, but not indicative of malicious intent.

### [medium] Unsafe memory aliasing

Finding ID: `NPS-1156E8A63724`

File: `internal/strs/strings_unsafe.go:21`

The UnsafeString and UnsafeBytes functions use unsafe.String and unsafe.Slice to create zero-copy conversions between []byte and string. If the caller violates the immutability contract, this can lead to data races, memory corruption, or unintended mutation of supposedly immutable strings. The code explicitly warns about this, but the API is inherently unsafe.

### [low] unsafe package usage

Finding ID: `NPS-FA5E110BFDD9`

File: `cmd/protoc-gen-go/testdata/proto2/fields.pb.go:1160`

Uses the unsafe package for efficient string/byte slicing, which is typical in protobuf generated code for performance. No memory corruption or exploitation patterns present.

### [low] init function

Finding ID: `NPS-01AECF470058`

File: `cmd/protoc-gen-go/testdata/proto2/fields.pb.go:1180`

The file contains an init() function that registers protobuf types with the runtime. This is standard generated code from protoc-gen-go and does not perform any malicious actions such as network requests, file system manipulation, or dynamic code execution.

### [low] Insecure file permissions

Finding ID: `NPS-FA05CE35DF7F`

File: `internal/cmd/generate-corpus/main.go:111`

The code uses os.WriteFile with permission 0777 when writing corpus files to internal/fuzz/... directories. This grants world-writable permissions, which could allow other local users to tamper with generated fuzz corpus files. While this is a test-only utility not run automatically, overly permissive file permissions are a security concern.

### [low] External command execution

Finding ID: `NPS-F0B2529434B7`

File: `internal/cmd/generate-protos/main.go:32`

The code executes external commands (git, go, protoc, diff) via os/exec. While these are legitimate development tools for code generation, executing external binaries can be a security concern if those binaries are compromised or if the PATH is manipulated.

### [low] Network access via external tools

Finding ID: `NPS-C5D639F04EA5`

File: `internal/cmd/generate-protos/main.go:38`

While the Go code itself does not make network requests, it invokes 'go list -m' which may access module proxies, and 'protoc' could potentially fetch remote resources depending on configuration.

### [low] Environment variable access

Finding ID: `NPS-2AD0940CE5CE`

File: `internal/cmd/generate-protos/main.go:52`

Reads environment variables PROTOBUF_ROOT and RUN_AS_PROTOC_PLUGIN. RUN_AS_PROTOC_PLUGIN is used to change program behavior, which could be exploited if an attacker can control the environment.

### [low] File system manipulation

Finding ID: `NPS-8184A7972837`

File: `internal/cmd/generate-protos/main.go:89`

The code writes generated files to the repository directory and creates temporary directories. It also modifies .proto files by generating hybrid/opaque variants. This is expected for a code generator but involves broad file system access.

### [low] Process execution

Finding ID: `NPS-48279C9C1E11`

File: `internal/cmd/generate-types/main.go:43`

The code executes external commands via os/exec: `git rev-parse --show-toplevel` is invoked twice (in main and chdirRoot), and `diff` is executed in writeSource when not in -execute mode. These are standard development tooling invocations for a code generator, but they do rely on the environment's git and diff binaries being present and trustworthy.

### [low] Working directory change based on external command output

Finding ID: `NPS-84C44875E53D`

File: `internal/cmd/generate-types/main.go:56`

chdirRoot changes the process working directory based on the output of `git rev-parse --show-toplevel`. If the working directory is inside a malicious or attacker-controlled git repository tree, this could redirect subsequent file writes. However, paths written are relative and constrained to the repo, so impact is limited.

### [low] File system write with world/group-writable permissions

Finding ID: `NPS-0594C09D9DA7`

File: `internal/cmd/generate-types/main.go:239`

writeSource writes generated files with mode 0664 (group-writable), which is slightly more permissive than the typical 0644. While not inherently malicious, group-writable source files can be modified by other users in the same group and is a minor hygiene concern.

### [low] Import-time file access

Finding ID: `NPS-1676D37C8663`

File: `internal/detrand/rand.go`

The package computes a hash of the host binary using os.Executable() and os.Open() at package initialization time via a package-level variable. While this is a legitimate technique documented by the Go project for deterministic randomness, reading the executable file at import time is unusual and could be repurposed for fingerprinting. No data is exfiltrated and the file read is limited to the program's own binary.

### [low] init-time code execution

Finding ID: `NPS-892914FFC659`

File: `internal/filedesc/editions.go:24`

The init() function runs at import time and unmarshals hardcoded edition defaults from a compiled-in byte slice (editiondefaults.Defaults). No external input, files, or network access is involved, and the code only performs protobuf decoding with bounded iteration.

### [low] Unchecked type assertion

Finding ID: `NPS-AF7FB48581EE`

File: `internal/impl/api_export_opaque.go:14`

UnmarshalField performs an unchecked type assertion msg.(protoreflect.ProtoMessage), which will panic if msg is not the expected type. This is a robustness issue, though not actively malicious.

### [low] unsafe pointer usage

Finding ID: `NPS-B5BE4E4B065C`

File: `internal/impl/pointer_unsafe.go`

The file heavily uses the unsafe package for pointer arithmetic and type conversions. While this is a legitimate technique for performance-critical reflection code in Go, it bypasses type safety and can lead to memory corruption if used incorrectly. The code is part of the official Go protobuf library and appears to be an internal implementation detail rather than a malicious pattern.

### [low] Potential race condition

Finding ID: `NPS-29205BC85E0B`

File: `internal/impl/presence.go:80`

The presence methods (e.g., PresentInCache, AnyPresent) use atomic loads but do not guarantee atomicity across multiple accesses or mutations, which could lead to data races if the bitmap is modified concurrently. The comment in LoadPresenceCache acknowledges that simultaneous mutation may cause inconsistent results. This is a correctness and security risk (e.g., time-of-check-time-of-use), but typical for performance-optimized code in a well-known library.

### [low] Lifetime management risk

Finding ID: `NPS-358CCC542C7D`

File: `internal/strs/strings_unsafe.go:51`

The Builder type allocates a byte buffer and returns strings via UnsafeString that reference slices of this buffer. If the Builder is reused or the buffer is reallocated, previously returned strings may become invalid or alias new data. This can cause subtle bugs and potential security issues if strings are used after the Builder's lifetime.

### [low] Code Generation / Initialization

Finding ID: `NPS-6DE6EB592A8E`

File: `internal/testprotos/test3/test_extension.pb.go`

This file is an auto-generated Go protobuf descriptor (protoc-gen-go). It defines protobuf extension metadata and an init() function that registers the file descriptor. The init() function only performs idempotent registration and does not exhibit malicious behavior such as network access, filesystem manipulation, or command execution.

### [low] Environment Variable Reading

Finding ID: `NPS-C82514EF79DA`

File: `reflect/protoregistry/registry.go:47`

The code reads the GOLANG_PROTOBUF_REGISTRATION_CONFLICT environment variable to control conflict handling policy. This is a documented and legitimate configuration mechanism, not credential harvesting.

## Files reviewed

- `internal/cmd/generate-corpus/main.go` (medium): No malicious intent detected; the code is a legitimate test corpus generator for Go protobuf fuzzing, but uses overly permissive 0777 file permissions when writing output files.
- `internal/cmd/generate-protos/main.go` (medium): This appears to be a legitimate protobuf code generation tool from the official Go protobuf repository, with only standard development tool interactions and no malicious behavior.
- `internal/cmd/generate-types/main.go` (medium): This is a standard Go protobuf code generator that invokes git and diff via os/exec and writes generated files; no data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found, only benign but notable subprocess and file-write behaviors.
- `internal/impl/api_export_opaque.go` (medium): This is a legitimate protobuf internal export shim using unsafe pointer operations and atomics for runtime support, with no evidence of exfiltration, credential harvesting, shell execution, or other malicious patterns, though its heavy use of unsafe memory manipulation warrants caution.
- `internal/impl/presence.go` (medium): The code is part of the official Go protobuf library and uses unsafe pointer arithmetic and atomic operations for performance, posing potential memory safety and race condition risks, but no malicious patterns were detected.
- `internal/strs/strings_unsafe.go` (medium): The code uses unsafe memory operations for performance, which introduces aliasing and lifetime risks but contains no malicious patterns such as exfiltration, backdoors, or code execution.
- `cmd/protoc-gen-go/internal_gengo/init.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/protoc-gen-go/internal_gengo/init_opaque.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/protoc-gen-go/internal_gengo/main.go` (safe): This is a legitimate protobuf code generator file with no malicious patterns detected.
- `cmd/protoc-gen-go/internal_gengo/opaque.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/protoc-gen-go/internal_gengo/reflect.go` (safe): This is standard Go protobuf code generation logic with no malicious patterns; generated init() functions only initialize protobuf descriptors as intended.
- `cmd/protoc-gen-go/internal_gengo/well_known_types.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/protoc-gen-go/main.go` (safe): No malicious patterns detected; this is the standard protoc-gen-go protobuf plugin entry point with no network, filesystem, or process manipulation beyond expected code generation.
- `cmd/protoc-gen-go/testdata/annotations/annotations.pb.go` (safe): No malicious patterns detected in this protoc-gen-go generated test data file.
- `cmd/protoc-gen-go/testdata/comments/comments.pb.go` (safe): This is a standard protoc-gen-go generated file with no malicious patterns, network calls, process execution, or credential access.
- `cmd/protoc-gen-go/testdata/comments/deprecated.pb.go` (safe): This is a standard protoc-gen-go generated file with no malicious patterns; initialization code only sets up protobuf type descriptors using the standard protobuf runtime.
- `cmd/protoc-gen-go/testdata/enumprefix/enumprefix.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf code for a test data enum prefix package.
- `cmd/protoc-gen-go/testdata/extensions/base/base.pb.go` (safe): No malicious patterns detected in this standard protobuf-generated Go file.
- `cmd/protoc-gen-go/testdata/extensions/ext/ext.pb.go` (safe): No malicious patterns detected in this generated protobuf Go file; it contains only standard protoc-gen-go output with no network, filesystem, process, or dynamic code execution activity.
- `cmd/protoc-gen-go/testdata/extensions/extra/extra.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/extensions/proto3/ext3.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code containing only type definitions, extension metadata, and descriptor initialization.
- `cmd/protoc-gen-go/testdata/featureresolution/basic.pb.go` (safe): This is a standard protoc-gen-go generated protobuf file for test data, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or suspicious network/process activity.
- `cmd/protoc-gen-go/testdata/features/test_features.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf code with no network, filesystem, process execution, or obfuscated behavior.
- `cmd/protoc-gen-go/testdata/fieldnames/fieldnames.pb.go` (safe): This is auto-generated protobuf Go code from the official Go toolchain testdata with no malicious patterns; the init() function only performs standard protobuf type registration.
- `cmd/protoc-gen-go/testdata/import_option/import_option.pb.go` (safe): No malicious patterns detected; the file is standard protoc-gen-go generated code containing only protobuf message definitions and initialization logic.
- `cmd/protoc-gen-go/testdata/import_option_custom/import_option_custom.pb.go` (safe): No malicious patterns detected in the generated protobuf Go code.
- `cmd/protoc-gen-go/testdata/import_option_unlinked/import_option_unlinked.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code with only init-time TypeBuilder registration and no network, filesystem, process, or obfuscated behavior.
- `cmd/protoc-gen-go/testdata/import_public/a.pb.go` (safe): This is standard protoc-gen-go generated Go code for protobuf testdata with no malicious patterns, network calls, credential access, or dynamic execution.
- `cmd/protoc-gen-go/testdata/import_public/b.pb.go` (safe): Generated protobuf Go code with no malicious patterns; only standard protobuf runtime usage and initialization.
- `cmd/protoc-gen-go/testdata/import_public/c.pb.go` (safe): No malicious patterns detected; this is a standard generated protobuf file with no network, filesystem, process, or dynamic code execution activity.
- `cmd/protoc-gen-go/testdata/import_public/sub/a.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/import_public/sub/b.pb.go` (safe): No malicious patterns detected in this generated protobuf Go source file
- `cmd/protoc-gen-go/testdata/import_public/sub2/a.pb.go` (safe): This is a standard protoc-gen-go generated file with only protobuf runtime code and no malicious patterns.
- `cmd/protoc-gen-go/testdata/imports/fmt/m.pb.go` (safe): This is auto-generated protobuf Go code from the official Google protobuf repository, containing only standard message registration and descriptor code with no malicious patterns.
- `cmd/protoc-gen-go/testdata/imports/test_a_1/m1.pb.go` (safe): Generated protobuf Go code with no malicious patterns detected; contains only standard protobuf runtime initialization and descriptor handling.
- `cmd/protoc-gen-go/testdata/imports/test_a_1/m2.pb.go` (safe): This is standard protoc-gen-go generated code with no malicious patterns, network calls, process execution, or credential access.
- `cmd/protoc-gen-go/testdata/imports/test_a_2/m3.pb.go` (safe): This is a standard protoc-gen-go generated file from the official Go protobuf repository containing only benign message type definitions and initialization code with no malicious patterns.
- `cmd/protoc-gen-go/testdata/imports/test_a_2/m4.pb.go` (safe): Auto-generated protobuf Go code with only standard init-time registration and no malicious patterns
- `cmd/protoc-gen-go/testdata/imports/test_b_1/m1.pb.go` (safe): This is standard machine-generated protobuf code from the official Go protobuf repository with no malicious patterns; the init() function only registers the message type descriptor.
- `cmd/protoc-gen-go/testdata/imports/test_b_1/m2.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code for a test message with no network, filesystem, process, or dynamic execution activity.
- `cmd/protoc-gen-go/testdata/imports/test_import_a1m1.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/imports/test_import_a1m2.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code with no network, filesystem, process, or credential access.
- `cmd/protoc-gen-go/testdata/imports/test_import_all.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf code from the official Go protobuf module with no network, filesystem, process, or obfuscated behavior.
- `cmd/protoc-gen-go/testdata/issue780_oneof_conflict/test.pb.go` (safe): Generated protobuf Go code for the Go standard library testdata; contains only standard serialization logic with no malicious patterns.
- `cmd/protoc-gen-go/testdata/nameclash/nameclash.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid/test_name_clash_hybrid.pb.go` (safe): This is standard, protoc-gen-go generated Go code from the official Google protobuf repository containing no malicious patterns, network calls, credential harvesting, dynamic code execution, or suspicious process spawning.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid/test_name_clash_hybrid_protoopaque.pb.go` (safe): This is generated protobuf Go code with only standard protoimpl/reflect/unsafe usage and no network, filesystem, process, or obfuscated behavior.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid3/test_name_clash_hybrid3_protoopaque.pb.go` (safe): No malicious patterns detected; this is a standard protoc-gen-go generated test file for name clash handling.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_opaque/test_name_clash_opaque.pb.go` (safe): Generated protobuf test code contains only standard serialization/deserialization logic with no malicious patterns, network calls, or dynamic execution.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_opaque3/test_name_clash_opaque3.pb.go` (safe): Generated protobuf test data code contains no suspicious network, filesystem, process, or obfuscated logic.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_open/test_name_clash_open.pb.go` (safe): This is a standard protoc-gen-go generated file from the official Go protobuf repository containing only message definitions, getters, and descriptor initialization with no malicious patterns.
- `cmd/protoc-gen-go/testdata/nameclash/test_name_clash_open3/test_name_clash_open3.pb.go` (safe): This is an autogenerated protobuf Go test fixture with no malicious patterns, network calls, exec/spawn logic, or sensitive data access.
- `cmd/protoc-gen-go/testdata/nopackage/nopackage.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/proto2/enum.pb.go` (safe): This is standard auto-generated protobuf Go code with no malicious patterns, network activity, credential access, or dynamic execution detected.
- `cmd/protoc-gen-go/testdata/proto2/fields.pb.go` (safe): This is standard generated protobuf code with no malicious patterns detected.
- `cmd/protoc-gen-go/testdata/proto2/nested_messages.pb.go` (safe): This is standard generated protobuf Go code from the official google.golang.org/protobuf repository with no malicious patterns or security concerns.
- `cmd/protoc-gen-go/testdata/proto2/proto2.pb.go` (safe): This is standard auto-generated protobuf Go code with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
- `cmd/protoc-gen-go/testdata/proto3/enum.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code with only benign init-time registration.
- `cmd/protoc-gen-go/testdata/proto3/fields.pb.go` (safe): No malicious patterns detected; this is a standard auto-generated protobuf Go file with no network, filesystem, process execution, or obfuscated code.
- `cmd/protoc-gen-go/testdata/protoeditions/enum.pb.go` (safe): No malicious patterns detected; this is a standard protoc-gen-go generated file with only benign serialization and enum initialization code.
- `cmd/protoc-gen-go/testdata/protoeditions/fields.pb.go` (safe): No malicious patterns detected; this is standard protoc-gen-go generated protobuf code with no network, filesystem, process, or obfuscation activity.
- `cmd/protoc-gen-go/testdata/protoeditions/legacy_enum.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/protoeditions/maps_and_delimited.pb.go` (safe): No malicious patterns detected; this is standard generated protobuf Go code from the official Go protobuf repository with no network, filesystem, process, or obfuscated behavior.
- `cmd/protoc-gen-go/testdata/protoeditions/nested_messages.pb.go` (safe): This is standard protoc-gen-go generated code for nested protobuf messages with no malicious patterns, network activity, obfuscation, or credential access.
- `cmd/protoc-gen-go/testdata/retention/options_message.pb.go` (safe): No malicious patterns detected
- `cmd/protoc-gen-go/testdata/retention/retention.pb.go` (safe): This is an automatically generated Go protobuf file from the official Go protobuf module containing only standard protobuf type definitions, reflection metadata, and initialization code with no malicious patterns.
- `cmd/protoc-gen-go/testdata/visibility/visibility.pb.go` (safe): This is standard protoc-gen-go generated code with no malicious patterns, network activity, or obfuscation.
- `compiler/protogen/protogen.go` (safe): No malicious patterns detected in the protogen package source; it is a standard Go protobuf code generator with expected file and network-adjacent operations limited to reading stdin/stdout and filesystem paths.
- `compiler/protogen/protogen_apilevel.go` (safe): Cleared by Jev triage; no further analysis needed
- `compiler/protogen/protogen_opaque.go` (safe): No malicious patterns detected; the code is a legitimate protobuf code generator helper with no network, filesystem, process, or dynamic execution activity.
- `encoding/protodelim/protodelim.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/protojson/decode.go` (safe): No malicious patterns detected; this is the standard Go protobuf JSON decoder implementation from the official google.golang.org/protobuf module.
- `encoding/protojson/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/protojson/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/protojson/well_known_types.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/prototext/decode.go` (safe): No malicious patterns detected
- `encoding/prototext/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/prototext/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/protowire/wire.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cmd/generate-types/impl.go` (safe): This is a legitimate protobuf code generation file using Go templates to produce wire encoding/decoding functions; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, backdoors, suspicious network activity, filesystem manipulation, or process spawning were detected.
- `internal/cmd/generate-types/impl_opaque.go` (safe): No malicious patterns detected
- `internal/cmd/generate-types/proto.go` (safe): No malicious patterns detected; the file contains legitimate protobuf wire type and Go type definitions used for generating serialization code.
- `internal/cmd/pbdump/pbdump.go` (safe): The code is a legitimate debugging tool from the Go protobuf repository that reads and decodes protocol buffer messages without any malicious patterns.
- `internal/descfmt/stringer.go` (safe): No malicious patterns detected; the code is a legitimate protobuf descriptor formatter with no network, filesystem, credential, or execution-related concerns.
- `internal/descopts/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/detrand/rand.go` (safe): The code is a legitimate Go standard-library-style package for deterministic randomness; it reads its own executable at init but performs no network, process, credential, or other malicious activity.
- `internal/editiondefaults/defaults.go` (safe): No malicious patterns detected; the file only embeds a static binary defaults file with no execution, network, or credential access.
- `internal/editionssupport/editions.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/defval/default.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/json/decode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/json/decode_number.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/json/decode_string.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/json/decode_token.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/json/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/messageset/messageset.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/tag/tag.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/decode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/decode_number.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/decode_string.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/decode_token.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/encoding/text/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/errors/errors.go` (safe): No malicious patterns detected
- `internal/filedesc/build.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/desc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/desc_init.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/desc_lazy.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/desc_list.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/desc_list_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/editions.go` (safe): This file is part of the official google.golang.org/protobuf module and contains only protobuf feature-set parsing logic with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or external command execution.
- `internal/filedesc/placeholder.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filedesc/presence.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/filetype/build.go` (safe): No malicious patterns detected
- `internal/flags/flags.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/flags/proto_legacy_disable.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/flags/proto_legacy_enable.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/fuzz/jsonfuzz/fuzz.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/fuzz/textfuzz/fuzz.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/fuzz/wirefuzz/fuzz.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/fuzztest/fuzztest.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/any_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/api_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/descriptor_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/duration_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/empty_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/field_mask_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/go_features_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/goname.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/map_entry.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/name.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/source_context_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/struct_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/timestamp_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/type_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/wrappers.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/genid/wrappers_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/api_export.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/bitmap.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/bitmap_race.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/checkinit.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_extension.go` (safe): No malicious patterns detected
- `internal/impl/codec_field.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_field_opaque.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_map.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_message.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_message_opaque.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_messageset.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_tables.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/codec_unsafe.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/convert.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/convert_list.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/convert_map.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/decode.go` (safe): No malicious patterns detected in this protobuf decoding implementation.
- `internal/impl/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/enum.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/equal.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/extension.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/lazy.go` (safe): The code is a legitimate part of the Go protobuf library implementing lazy unmarshaling; it contains no malicious patterns such as data exfiltration, credential harvesting, backdoors, or suspicious network/process activity.
- `internal/impl/legacy_enum.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/legacy_export.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/legacy_extension.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/legacy_file.go` (safe): No malicious patterns detected; the code is a legitimate part of the Go protobuf library for loading legacy file descriptors with gzip decompression and caching.
- `internal/impl/legacy_message.go` (safe): This file is part of the official Go protobuf runtime (google.golang.org/protobuf) and contains only legitimate legacy message reflection/wrapping logic with no malicious patterns.
- `internal/impl/merge.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/merge_gen.go` (safe): No malicious patterns detected
- `internal/impl/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_opaque.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_opaque_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_reflect.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_reflect_field.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_reflect_field_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/message_reflect_gen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/impl/pointer_unsafe.go` (safe): No malicious patterns detected; the code uses unsafe pointer operations for performance but is part of the official Go protobuf library.
- `internal/impl/pointer_unsafe_opaque.go` (safe): No malicious patterns detected
- `internal/impl/validate.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/msgfmt/format.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/order/order.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/order/range.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pragma/pragma.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/protobuild/build.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/protolazy/bufferreader.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/protolazy/lazy.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/protolazy/pointer_unsafe.go` (safe): No malicious patterns detected
- `internal/protolegacy/proto.go` (safe): No malicious patterns detected in this legacy protocol stub implementation.
- `internal/set/ints.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/strs/strings.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testprotos/annotation/annotation.pb.go` (safe): Generated protobuf code for an internal test annotation with no malicious patterns, network activity, or dynamic execution.
- `internal/testprotos/benchmarks/benchmarks.pb.go` (safe): No malicious patterns detected; this is a standard protoc-gen-go generated file for benchmark protobuf definitions.
- `internal/testprotos/benchmarks/datasets/google_message1/proto2/benchmark_message1_proto2.pb.go` (safe): This is a standard protoc-gen-go generated file for benchmark protobuf messages with no malicious patterns, dynamic execution, network activity, or filesystem manipulation.
- `internal/testprotos/benchmarks/datasets/google_message1/proto3/benchmark_message1_proto3.pb.go` (safe): No malicious patterns detected in this generated protobuf file; it contains only standard boilerplate message definitions and initialization code.
- `internal/testprotos/benchmarks/datasets/google_message2/benchmark_message2.pb.go` (safe): This is a standard protoc-gen-go generated file for benchmark protobuf messages with no malicious patterns, network activity, credential harvesting, or dynamic code execution.
- `internal/testprotos/benchmarks/datasets/google_message3/benchmark_message3_7.pb.go` (safe): This is a standard protoc-gen-go generated file containing only Protocol Buffer message definitions with no malicious activity, network operations, or suspicious behavior.
- `internal/testprotos/benchmarks/micro/micro.pb.go` (safe): No malicious patterns detected; the file is standard generated protobuf Go code with no network, filesystem, process, or dynamic execution activity.
- `internal/testprotos/conformance/conformance.pb.go` (safe): This is a standard protoc-generated Go file for Protocol Buffers conformance testing with no malicious patterns, external calls, or suspicious behavior.
- `internal/testprotos/conformance/editions/test_messages_edition2023.pb.go` (safe): This is a standard protoc-gen-go generated file from the official Google Protocol Buffers repository containing no malicious patterns, network calls, credential harvesting, or dynamic code execution.
- `internal/testprotos/conformance/editionsmigration/test_messages_proto3_editions.pb.go` (safe): This is a standard protoc-gen-go generated Go file for a test protobuf schema with no malicious patterns, network activity, credential access, or dynamic code execution.
- `internal/testprotos/conformance/editionunstable/test_messages_edition_unstable.pb.go` (safe): No malicious patterns detected; the file is standard protoc-gen-go generated code with normal init registration and no network, filesystem, process, or dynamic-execution activity.
- `internal/testprotos/conformance/test_messages_proto3.pb.go` (safe): No malicious patterns detected in this protoc-generated Go file, which contains only standard protobuf message definitions, getters, and reflection metadata.
- `internal/testprotos/editionsfuzztest/test2.pb.go` (safe): No malicious patterns detected; this is a standard protoc-gen-go generated file for protocol buffer test types.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
