Directories
¶
| Path | Synopsis |
|---|---|
|
analyzers
|
|
|
discardmutator
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success.
|
Package discardmutator catches security-state mutations whose result is discarded right where the handler acknowledges success. |
|
errleak
Package errleak catches an internal error string being handed to the client on a 5xx response.
|
Package errleak catches an internal error string being handed to the client on a 5xx response. |
|
fieldtypeswitch
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard.
|
Package fieldtypeswitch makes adding a schema field type a checklist instead of a silent hazard. |
|
fmtformat
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string.
|
Package fmtformat catches URL-encoder output (url.Values.Encode, url.QueryEscape, url.PathEscape) becoming part of a fmt format string. |
|
hygiene
Package hygiene holds the small checks whose whole point is that they currently find nothing.
|
Package hygiene holds the small checks whose whole point is that they currently find nothing. |
|
mapwriter
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render.
|
Package mapwriter catches nondeterministic SSR output at its source: ranging over a Go map while writing into an output builder emits attributes/markup in a different order every render. |
|
reqparamlimit
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters.
|
Package reqparamlimit catches unclamped request-sourced integers flowing into limit/cap-shaped call parameters. |
|
testgap
Package testgap reports validator enumeration arms that no fixture in the package ever exercises.
|
Package testgap reports validator enumeration arms that no fixture in the package ever exercises. |
|
unboundedbody
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory.
|
Package unboundedbody catches an inbound HTTP request body that is read or decoded without a size cap, so a single request can spend the server's memory. |
|
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch.
|
Package browserpath resolves the Chrome/Chromium/Edge executable that chromedp should launch. |
|
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree.
|
Package pgtest provides a shared real-Postgres test harness usable from any package in the module (core/migrate, cmd/gofastr, …) without importing framework/internal/testdb, which is import-restricted to the framework tree. |
Click to show internal directories.
Click to hide internal directories.