# 使用 Homebrew, apk, dnf, MacPorts, Nix, zypper, scoop 安装 gosec

查看 gosec 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:gosec
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install gosec
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install gosec
```

  证据: MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add gosec
```

  证据: Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- dnf (92%):

```sh
sudo dnf install gosec
```

  证据: Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#gosec
```

  证据: nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install gosec
```

  证据: openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Scoop (92%):

```sh
scoop install main/gosec
```

  证据: Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:gosec
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/gosec>
- **版本:** 2.28.0
- **来源摘要:** Golang security checker
- **主页:** <https://securego.io/>
- **仓库:** <https://github.com/securego/gosec>
- **上游文档:** <https://securego.io/>
- **许可证:** Apache-2.0
- **源码归档:** <https://github.com/securego/gosec/archive/refs/tags/v2.28.0.tar.gz>
- **最后更新:** 2026-07-29T16:05:04+02:00
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- gosec (cli)
- gosec (别名)

## 依赖

- go

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 2.28.0
- 管理器更新时间: 2026-07-29
- 本地数据: OK
- 上游仓库: https://github.com/securego/gosec
- 检测到的最新版本: v2.28.0 (当前)
## 项目历史与用法

gosec is the SecureGo project's static security scanner for Go source code, using AST, SSA, and taint-analysis rules to find common vulnerability patterns before code ships.

### 项目历史

The GitHub repository was created on July 18, 2016. Its README describes gosec as a Go security checker that inspects source code by scanning Go AST and SSA representations, while SecureGo's tools page frames the project as a way to programmatically enforce Secure Go guidelines.

Over time the project expanded from pattern-style checks into a broader rule catalog. Official rule documentation groups findings by general secure coding, injection, filesystem permissions, crypto and protocol security, import blocklists, language/runtime safety, and taint analysis. The README also documents CWE mapping, SARIF output, GitHub Action usage, Go analysis integration, and configurable global and per-rule settings.

### 采用历史

gosec became a standard Go security linter because it fits normal Go and CI workflows: go install for local use, a GitHub Action for repository scanning, SARIF output for GitHub code scanning, and package-manager distribution through apk, Homebrew, dnf, MacPorts, Nix, Scoop, and zypper according to the input package facts.

The project sits in the same practical lane as go vet and staticcheck but focuses on security-sensitive APIs and data flows. Its CII Best Practices badge, GitHub Action, Go analysis package, and package-manager coverage made it accessible both to individual Go developers and to teams wiring security checks into CI.

### 使用方式

The basic local workflow is gosec ./..., with options for JSON or SARIF reports, selected rule inclusion or exclusion, and a config.json file passed through -conf. CI workflows often run securego/gosec as an action and upload SARIF to GitHub code scanning.

gosec rules include hardcoded credentials, unchecked errors, unsafe usage, SQL and command injection patterns, archive/path traversal risks, TLS and crypto weaknesses, blocklisted imports, integer/slice issues, and taint-analysis checks for SQL injection, command injection, SSRF, XSS, log injection, SMTP injection, server-side template injection, unsafe deserialization, and open redirects.

### 为什么软件包爱好者会关心

For package maintainers, gosec is important because it is easy to add as a single CLI check across Go packages without adopting a SaaS scanner. It gives distro and CI users a reproducible local executable, machine-readable output, CWE mappings, and a documented config file.

Its package-manager footprint also matters: a security scanner being available from Homebrew, Linux distro channels, Nix, Scoop, and container/GitHub Action paths means the same scanner can be used by laptop developers, CI jobs, and release pipelines.

### 时间线

- 2016-07-18: GitHub repository created
- 2020: SecureGo site documented gosec as a tool for programmatically enforcing Secure Go guidelines
- v2 era: Module path and docs center on github.com/securego/gosec/v2
- README era: GitHub Action, SARIF, Go analysis integration, and config-file workflows documented
- Rule-docs era: Rule catalog organized across AST, SSA, and taint-analysis checks

### Related projects

- SecureGo guidelines provide the surrounding secure-coding project context.
- GitHub code scanning consumes gosec SARIF output in documented workflows.
- golang.org/x/tools/go/analysis is supported through gosec's analyzer integration.
- Bazel nogo is named in the README as an integration target for the analyzer package.

### 来源

- <https://github.com/marketplace/actions/gosec-security-checker>
- <https://github.com/securego/gosec>
- <https://raw.githubusercontent.com/securego/gosec/master/README.md>
- <https://raw.githubusercontent.com/securego/gosec/master/RULES.md>
- <https://securego.io/docs/tools>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config.json
## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** gosec
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 其他软件包管理器记录

- Nix - gosec: normalized package name match | nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - gosec - 2.28.0-r0: normalized package name match | Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Go source code static analyzer, focusing on security | https://github.com/securego/gosec
- dnf - gosec - 2.28.0-2.fc45: normalized package name match | Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | Go security checker | https://github.com/securego/gosec
- zypper - gosec - 2.28.0-1.1: normalized package name match | openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | CLI tool to scan the Go AST and SSA code representations for security problems | https://github.com/securego/gosec
- MacPorts - gosec: normalized package name match | MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/gosec: normalized package name match | Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## 相关链接

- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Developer build packages](https://pkg.so/zh-hans/developer-build-tools/) - Matched build, compiler, generator, or developer workflow metadata.
- [Language runtime packages](https://pkg.so/zh-hans/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [go](https://pkg.so/zh-hans/brew/go/) - Runtime dependency declared by Homebrew.
- [xk6](https://pkg.so/zh-hans/brew/xk6/) - Popular package that depends on this formula.
- [intercept](https://pkg.so/zh-hans/brew/intercept/) - Shares pkgdb curated category or tags: cli, sast, security, static-analysis.
- [zizmor](https://pkg.so/zh-hans/brew/zizmor/) - Shares pkgdb curated category or tags: cli, security, static-analysis.
- [checkov](https://pkg.so/zh-hans/brew/checkov/) - Shares pkgdb curated category or tags: cli, security, static-analysis.
- [tfsec](https://pkg.so/zh-hans/brew/tfsec/) - Shares pkgdb curated category or tags: cli, security, static-analysis.
- [osv-scanner](https://pkg.so/zh-hans/brew/osv-scanner/) - Shares pkgdb curated category or tags: cli, go, security.
- [gobuster](https://pkg.so/zh-hans/brew/gobuster/) - Shares pkgdb curated category or tags: cli, go, security.
- [govulncheck](https://pkg.so/zh-hans/brew/govulncheck/) - Shares pkgdb curated category or tags: cli, go, security.
- [terrascan](https://pkg.so/zh-hans/brew/terrascan/) - Shares pkgdb curated category or tags: cli, security, static-analysis.
- [apkleaks](https://pkg.so/zh-hans/brew/apkleaks/) - Security-sensitive metadata or terminology overlaps. Shared terms: analysis, cli, scanner, security, static.
- [noir](https://pkg.so/zh-hans/brew/noir/) - Security-sensitive metadata or terminology overlaps. Shared terms: analysis, cli, sast, security, static.

## Combined YAML source

View the package source record on GitHub. [combined/gosec.yml](https://github.com/mxcl/pkgdb/blob/main/combined/gosec.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
