# 使用 Homebrew, apk, dnf, MacPorts, Nix, zypper, scoop 安装 gosec

查看 gosec 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:gosec
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install gosec
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install gosec
```

  证据: MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add gosec
```

  证据: Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- dnf (92%):

```sh
sudo dnf install gosec
```

  证据: Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#gosec
```

  证据: nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install gosec
```

  证据: openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Scoop (92%):

```sh
scoop install main/gosec
```

  证据: Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:gosec
- **软件包管理器:** Homebrew
- **版本:** 2.28.0
- **来源摘要:** Golang security checker
- **主页:** <https://securego.io/>
- **仓库:** <https://github.com/securego/gosec>
- **最后更新:** 2026-07-29T16:05:04+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- gosec (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 2.28.0
## 项目历史与用法

gosec is the SecureGo project's static security scanner for Go source code, using AST, SSA, and taint-analysis rules to find common vulnerability patterns before code ships.

### 项目历史

The GitHub repository was created on July 18, 2016. Its README describes gosec as a Go security checker that inspects source code by scanning Go AST and SSA representations, while SecureGo's tools page frames the project as a way to programmatically enforce Secure Go guidelines.

Over time the project expanded from pattern-style checks into a broader rule catalog. Official rule documentation groups findings by general secure coding, injection, filesystem permissions, crypto and protocol security, import blocklists, language/runtime safety, and taint analysis. The README also documents CWE mapping, SARIF output, GitHub Action usage, Go analysis integration, and configurable global and per-rule settings.

### 采用历史

gosec became a standard Go security linter because it fits normal Go and CI workflows: go install for local use, a GitHub Action for repository scanning, SARIF output for GitHub code scanning, and package-manager distribution through apk, Homebrew, dnf, MacPorts, Nix, Scoop, and zypper according to the input package facts.

The project sits in the same practical lane as go vet and staticcheck but focuses on security-sensitive APIs and data flows. Its CII Best Practices badge, GitHub Action, Go analysis package, and package-manager coverage made it accessible both to individual Go developers and to teams wiring security checks into CI.

### 使用方式

The basic local workflow is gosec ./..., with options for JSON or SARIF reports, selected rule inclusion or exclusion, and a config.json file passed through -conf. CI workflows often run securego/gosec as an action and upload SARIF to GitHub code scanning.

gosec rules include hardcoded credentials, unchecked errors, unsafe usage, SQL and command injection patterns, archive/path traversal risks, TLS and crypto weaknesses, blocklisted imports, integer/slice issues, and taint-analysis checks for SQL injection, command injection, SSRF, XSS, log injection, SMTP injection, server-side template injection, unsafe deserialization, and open redirects.

### 为什么软件包爱好者会关心

For package maintainers, gosec is important because it is easy to add as a single CLI check across Go packages without adopting a SaaS scanner. It gives distro and CI users a reproducible local executable, machine-readable output, CWE mappings, and a documented config file.

Its package-manager footprint also matters: a security scanner being available from Homebrew, Linux distro channels, Nix, Scoop, and container/GitHub Action paths means the same scanner can be used by laptop developers, CI jobs, and release pipelines.

### 时间线

- 2016-07-18: GitHub repository created
- 2020: SecureGo site documented gosec as a tool for programmatically enforcing Secure Go guidelines
- v2 era: Module path and docs center on github.com/securego/gosec/v2
- README era: GitHub Action, SARIF, Go analysis integration, and config-file workflows documented
- Rule-docs era: Rule catalog organized across AST, SSA, and taint-analysis checks

### Related projects

- SecureGo guidelines provide the surrounding secure-coding project context.
- GitHub code scanning consumes gosec SARIF output in documented workflows.
- golang.org/x/tools/go/analysis is supported through gosec's analyzer integration.
- Bazel nogo is named in the README as an integration target for the analyzer package.

### 来源

- <https://github.com/marketplace/actions/gosec-security-checker>
- <https://github.com/securego/gosec>
- <https://raw.githubusercontent.com/securego/gosec/master/README.md>
- <https://raw.githubusercontent.com/securego/gosec/master/RULES.md>
- <https://securego.io/docs/tools>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config.json
## 其他软件包管理器记录

- Nix - gosec: normalized package name match | nixpkgs package indexes: pkgs/by-name/go/gosec/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - gosec - 2.28.0-r0: normalized package name match | Alpine Linux edge package indexes: gosec from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Go source code static analyzer, focusing on security | https://github.com/securego/gosec
- dnf - gosec - 2.28.0-2.fc45: normalized package name match | Fedora Rawhide package metadata: gosec from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | Go security checker | https://github.com/securego/gosec
- zypper - gosec - 2.28.0-1.1: normalized package name match | openSUSE Tumbleweed package metadata: gosec from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | CLI tool to scan the Go AST and SSA code representations for security problems | https://github.com/securego/gosec
- MacPorts - gosec: normalized package name match | MacPorts ports tree: security/gosec/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/gosec: normalized package name match | Scoop official bucket manifest trees: bucket/gosec.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/gosec.yml](https://github.com/mxcl/pkgdb/blob/main/combined/gosec.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
