# Installer gosec avec Homebrew, apk, dnf, MacPorts, Nix, zypper, scoop

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de gosec pour les workflows d'agents IA.

## installation

```sh
sudo av install brew:gosec
```

Commandes d'installation supplémentaires:

### macOS

- Homebrew (100%):

```sh
brew install gosec
```

  Preuve: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install gosec
```

  Preuve: MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add gosec
```

  Preuve: Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- dnf (92%):

```sh
sudo dnf install gosec
```

  Preuve: Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#gosec
```

  Preuve: nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install gosec
```

  Preuve: openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Scoop (92%):

```sh
scoop install main/gosec
```

  Preuve: Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## Faits du paquet

- **Clé du paquet:** brew:gosec
- **Gestionnaire de paquets:** Homebrew
- **Version:** 2.28.0
- **Résumé source:** Golang security checker
- **Page d'accueil:** <https://securego.io/>
- **Dépôt:** <https://github.com/securego/gosec>
- **Dernière mise à jour:** 2026-07-29T16:05:04+02:00
- **Généré:** 2026-08-03T19:37:03+00:00

## exécutables

- gosec (alias)

## Comportement d'installation

- Bouteille: non disponible

## Version et fraîcheur

- page générée: 2026-08-03
- version du gestionnaire: 2.28.0
## Historique du projet et usages

gosec is the SecureGo project's static security scanner for Go source code, using AST, SSA, and taint-analysis rules to find common vulnerability patterns before code ships.

### Historique du projet

The GitHub repository was created on July 18, 2016. Its README describes gosec as a Go security checker that inspects source code by scanning Go AST and SSA representations, while SecureGo's tools page frames the project as a way to programmatically enforce Secure Go guidelines.

Over time the project expanded from pattern-style checks into a broader rule catalog. Official rule documentation groups findings by general secure coding, injection, filesystem permissions, crypto and protocol security, import blocklists, language/runtime safety, and taint analysis. The README also documents CWE mapping, SARIF output, GitHub Action usage, Go analysis integration, and configurable global and per-rule settings.

### Historique d'adoption

gosec became a standard Go security linter because it fits normal Go and CI workflows: go install for local use, a GitHub Action for repository scanning, SARIF output for GitHub code scanning, and package-manager distribution through apk, Homebrew, dnf, MacPorts, Nix, Scoop, and zypper according to the input package facts.

The project sits in the same practical lane as go vet and staticcheck but focuses on security-sensitive APIs and data flows. Its CII Best Practices badge, GitHub Action, Go analysis package, and package-manager coverage made it accessible both to individual Go developers and to teams wiring security checks into CI.

### Modes d'utilisation

The basic local workflow is gosec ./..., with options for JSON or SARIF reports, selected rule inclusion or exclusion, and a config.json file passed through -conf. CI workflows often run securego/gosec as an action and upload SARIF to GitHub code scanning.

gosec rules include hardcoded credentials, unchecked errors, unsafe usage, SQL and command injection patterns, archive/path traversal risks, TLS and crypto weaknesses, blocklisted imports, integer/slice issues, and taint-analysis checks for SQL injection, command injection, SSRF, XSS, log injection, SMTP injection, server-side template injection, unsafe deserialization, and open redirects.

### Pourquoi les passionnés de paquets s'y intéressent

For package maintainers, gosec is important because it is easy to add as a single CLI check across Go packages without adopting a SaaS scanner. It gives distro and CI users a reproducible local executable, machine-readable output, CWE mappings, and a documented config file.

Its package-manager footprint also matters: a security scanner being available from Homebrew, Linux distro channels, Nix, Scoop, and container/GitHub Action paths means the same scanner can be used by laptop developers, CI jobs, and release pipelines.

### Chronologie

- 2016-07-18: GitHub repository created
- 2020: SecureGo site documented gosec as a tool for programmatically enforcing Secure Go guidelines
- v2 era: Module path and docs center on github.com/securego/gosec/v2
- README era: GitHub Action, SARIF, Go analysis integration, and config-file workflows documented
- Rule-docs era: Rule catalog organized across AST, SSA, and taint-analysis checks

### Related projects

- SecureGo guidelines provide the surrounding secure-coding project context.
- GitHub code scanning consumes gosec SARIF output in documented workflows.
- golang.org/x/tools/go/analysis is supported through gosec's analyzer integration.
- Bazel nogo is named in the README as an integration target for the analyzer package.

### Sources

- <https://github.com/marketplace/actions/gosec-security-checker>
- <https://github.com/securego/gosec>
- <https://raw.githubusercontent.com/securego/gosec/master/README.md>
- <https://raw.githubusercontent.com/securego/gosec/master/RULES.md>
- <https://securego.io/docs/tools>


## Notes de sécurité

narrow executable package without higher-risk signals.

- **Risque Geiger:** vert / faible
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config.json
## Autres enregistrements de gestionnaires de paquets

- Nix - gosec: normalized package name match | nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - gosec - 2.28.0-r0: normalized package name match | Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Go source code static analyzer, focusing on security | https://github.com/securego/gosec
- dnf - gosec - 2.28.0-2.fc45: normalized package name match | Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | Go security checker | https://github.com/securego/gosec
- zypper - gosec - 2.28.0-1.1: normalized package name match | openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | CLI tool to scan the Go AST and SSA code representations for security problems | https://github.com/securego/gosec
- MacPorts - gosec: normalized package name match | MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/gosec: normalized package name match | Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/gosec.yml](https://github.com/mxcl/pkgdb/blob/main/combined/gosec.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
