{"id":2316,"date":"2022-01-18T10:11:16","date_gmt":"2022-01-18T01:11:16","guid":{"rendered":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/?p=2316"},"modified":"2022-10-29T22:22:57","modified_gmt":"2022-10-29T13:22:57","slug":"install-gosec","status":"publish","type":"post","link":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2022\/01\/18\/install-gosec\/","title":{"rendered":"gosec\u3092Github Actions\u3092\u7528\u3044\u3066\u5c0e\u5165\u3057\u305f\u8a71"},"content":{"rendered":"
The Gopher character is based on the Go mascot designed by Ren\u00e9e French.<\/p>\n
\u3000\u3053\u3093\u306b\u3061\u306f\uff01\u5165\u793e\u3057\u3066\u3082\u3046\u3059\u3050\u534a\u5e74\u304c\u7d4c\u3068\u3046\u3068\u3057\u3066\u304a\u308a\u307e\u3059\u3001\u3053\u307e\u3067\u3059\u3002
\n\u65e5\u3005\u60a9\u307f\u3064\u3064\u3082\u697d\u3057\u304f\u904e\u3054\u3057\u3066\u3044\u305f\u3089\u3001\u3042\u3063\u3068\u3044\u3046\u9593\u3067\u3059\u306d\u3002<\/p>\n
\u3000\u3055\u3066\u3001\u4eca\u56de\u306fgosec\u3092\u5c0e\u5165\u3057\u305f\u304a\u8a71\u3092\u66f8\u3044\u3066\u307f\u3088\u3046\u3068\u601d\u3044\u307e\u3059\u3002
\n\u79c1\u306f\u666e\u6bb5golang\u3092\u4f7f\u3063\u3066\u5b9f\u88c5\u3057\u3066\u3044\u308b\u306e\u3067\u3059\u304c\u3001\u300c\u30bb\u30ad\u30e5\u30a2\u306a\u30b3\u30fc\u30c9\u3092\u66f8\u304f\u3053\u3068\u304c\u3067\u304d\u3066\u3044\u308b\u304b\uff1f\u300d\u3068\u3044\u3046\u89b3\u70b9\u3092\u3082\u3063\u3066\u30b3\u30fc\u30c9\u3092\u66f8\u304f\u3053\u3068\u306f\u975e\u5e38\u306b\u5927\u5207\u3067\u3059\u3088\u306d\u3002<\/p>\n
\u554f\u984c\u306f\u3001\u300c\u5e38\u306b\u30bb\u30ad\u30e5\u30a2\u306a\u5b9f\u88c5\u304c\u3067\u304d\u3066\u3044\u308b\u304b\uff1f\u300d\u3068\u3044\u3046\u3053\u3068\u3067\u3059\u3002<\/p>\n
\u3053\u3046\u3044\u3063\u305f\u554f\u984c\u3092\u89e3\u6c7a\u3057\u3066\u304f\u308c\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c4\u30fc\u30eb\u3001\u305d\u308c\u304c\u300cgosec<\/a><\/strong>\u300d\u3067\u3059\u3002<\/p>\n \u3000gosec\u306fSAST\uff08Static application security testing\uff09\u306e\u4e00\u7a2e\u3067\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u6b20\u9665\u306b\u3064\u3044\u3066\u3001golang\u306e\u9759\u7684\u30b3\u30fc\u30c9\u5206\u6790\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n \u3000\u4eca\u56de\u306fgosec\u3092\u4f7f\u7528\u3057\u3066\u3001\u30d7\u30eb\u30ea\u30af\u30a8\u30b9\u30c8\u767a\u884c\u6642\u306b\u4ee5\u4e0b\u304c\u81ea\u52d5\u3067\u884c\u308f\u308c\u308b\u3088\u3046\u5b9f\u88c5\u3092\u884c\u3044\u307e\u3057\u305f\u3002\uff08\u203b\u4ee5\u964d\u306b\u8a18\u8f09\u3057\u3066\u3044\u308b\u624b\u9806\u306fgosec v2.9.5<\/a>\u6642\u70b9\u306eREADME\u3092\u53c2\u7167\u3057\u3066\u304a\u308a\u307e\u3059\u3002\uff09<\/p>\n \u3000gosec\u3092Github Actions\u3078\u5c0e\u5165\u3059\u308b\u306b\u3042\u305f\u308a\u3001\u6b21\u306e2\u70b9\u306e\u61f8\u5ff5\u4e8b\u9805\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n \u3053\u3046\u306a\u308b\u3068\u3001\u78ba\u8a8d\u3084\u5bfe\u5fdc\u304c\u5927\u5909\u306b\u306a\u308a\u3001\u30a2\u30e9\u30fc\u30c8\u304c\u5f62\u9ab8\u5316\u3057\u3066\u3057\u307e\u3046\u30ea\u30b9\u30af<\/strong>\u304c\u767a\u751f\u3057\u307e\u3059\u3002<\/p>\n \u3000\u305d\u3053\u3067\u4eca\u56de\u306f\u3001\u30d7\u30eb\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u3066\u5dee\u5206\u304c\u3042\u3063\u305f\u7b87\u6240\u306b\u306e\u307f\u30b3\u30e1\u30f3\u30c8\u3092\u6295\u7a3f\u3057\u3066\u304f\u308c\u308b<\/strong>reviewdog\u3068gosec\u3092\u30b3\u30e9\u30dc\u30ec\u30fc\u30b7\u30e7\u30f3\u3055\u305b\u308b\u3053\u3068\u306b\u3057\u307e\u3057\u305f\u3002\u3082\u3061\u308d\u3093\u6700\u7d42\u7684\u306b\u306f\u5168\u30ea\u30b9\u30af\u3092\u89e3\u6d88\u5243\u308b\u5fc5\u8981\u306f\u3042\u308a\u307e\u3059\u304c\u3001\u5dee\u5206\u306b\u95a2\u308f\u308b\u30a2\u30e9\u30fc\u30c8\u306f\u53d6\u308a\u6025\u304ereviewdog\u304b\u3089\u78ba\u8a8d\u53ef\u80fd\u3067\u3059\u3002<\/p>\n golangci-lint<\/a>\u306eAction\u3092\u5229\u7528\u3057\u3066\u7c21\u5358\u306b\u5b9f\u88c5\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n \u3055\u3089\u306b \u30d7\u30eb\u30ea\u30af\u30a8\u30b9\u30c8\u4e0a\u3067\u3001G404\u30a8\u30e9\u30fc\u304c\u8868\u793a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n <\/p>\n Annotations\u306e\u30a2\u30e9\u30fc\u30c8\u306f\u4ee5\u4e0b\u306e\u69d8\u306b\u51fa\u529b\u3055\u308c\u307e\u3057\u305f\u3002\u5dee\u5206\u306b\u304b\u304b\u3089\u306a\u3044\u3082\u306e\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002gosec\u306e\u7279\u5fb4<\/h2>\n
gosec\u306e\u30e1\u30ea\u30c3\u30c8<\/h3>\n
\n
\u5b8c\u6210\u5f62<\/h2>\n
\n
\u5c0e\u5165<\/h2>\n
1. reviewdog\u7d4c\u7531\u3067gosec\u306e\u30ec\u30d3\u30e5\u30fc\u7d50\u679c\u3092\u8868\u793a\u3055\u305b\u308b<\/h3>\n
\n
reviewdog\u3078\u306egosec\u306e\u7d44\u307f\u8fbc\u307f<\/h4>\n
name: reviewdog\non: [pull_request]\njobs:\n reviewdog:\n runs-on: ubuntu-latest\n env:\n GO111MODULE: on\n steps:\n - name: Checkout Source\n uses: actions\/checkout@v2\n\n - name: Run golangci-lint\n uses: reviewdog\/action-golangci-lint@v2\n with:\n github_token: ${{ secrets.GITHUB_TOKEN }}\n level: info\n golangci_lint_flags: "--config=.github\/.golangci.yml"\n # \u5dee\u5206\u4ee5\u5916\u306e\u30a2\u30e9\u30fc\u30c8\u3092Actions\u306e"Annotations"\u3088\u308a\u78ba\u8a8d\u53ef\u80fd\u306b\u3059\u308b\n filter_mode: nofilter\n reporter: github-pr-review<\/code><\/pre>\n
.github\/.golangci.yml<\/code>\u306b\u3066linter\u306bgosec\u3092\u6307\u5b9a\u3059\u308c\u3070\u3001\u5b8c\u4e86\u3067\u3059\u3002\uff08\u53c2\u8003\uff1ahttps:\/\/golangci-lint.run\/usage\/configuration\/<\/a>\uff09<\/p>\n
linters:\n disable-all: true\n enable:\n - gosec\n\nissues:\n exclude-use-default: false\n\ngosec:\n exclude-generated: true\n severity: "low"\n confidence: "low"<\/code><\/pre>\n
\u7d44\u307f\u8fbc\u307f\u7d50\u679c<\/h4>\n
\n<\/p>\n2. Github Actions\u3092\u7528\u3044\u3066\u3001gosec\u306e\u30ec\u30d3\u30e5\u30fc\u7d50\u679c\u3092html\u30ec\u30dd\u30fc\u30c8\u3067\u51fa\u529b\u3059\u308b<\/h3>\n