7 ms·
As the article also mentions: instead of checking if your program has a dependency on something that contains vulnerabilities, govulncheck checks if vulnerable
by rollulus 2y ago
As the article also mentions: instead of checking if your program has a dependency on something that contains vulnerabilities, govulncheck checks if vulnerable code is actually reached. I find that so awesome. (And I know, someone is going to point out that hipster language foo does this too and better — it’s not the norm).
- lynx23 2y ago> hipster language Funny, I always considered Go a hipster language for Google fanboys.
- paulddraper 2y agoYou either die a hipster or live long enough to become mainstream.
- Cthulhu_ 2y agoGo is a retro nostalgia language, taking programming languages back to basics, removing syntax highlighting and advanced concepts like exceptions and function shorthands because that's what it was like in the 70's.
- euroderf 2y agoI'll give up my Go when you pry this PDP-11 emulation from my cold, dead hand.
- rob74 2y agoPray tell, what is it about Go that stops editors from using syntax highlighting when displaying Go code? Seriously, IMHO Go is less "retro nostalgia" and more trying to stick to proven concepts (e.g. there was no test driven development in the 70s, and Go has testing/documentation/examples built into the language) while leaving out things like exceptions and inheritance that, while widespread, have significant disadvantages.
- silverliver 2y agoPerhaps, but all I really care about is having a complied, strongly-typed language with a fully-featured modern stdlib and good cross-compilation support that includes wasm. If that comes with an automatic admission to the Google Fanboy Club, then sign me up. What other well-established languages do we have that meet this criteria? I know .net is a strong contender but do we have other options?
- vlovich123 2y agoRust & Java also come to mind (yes, Java can be AOT compiled). Erlang too if you want more fearless concurrency if you’re OK with JIT languages. There’s lots of alternatives to Go in its space but it does have mindshare and there’s nothing wrong with staying on the well trodden path even if it’s full of if err != nil instead of sane error chaining built into the language.
- pjmlp 2y agoRegarding Java, since early 2000 to be more precisely, although it required paying for commercial JDKs like Excelsior JET. Nowadays besides the more well known GraalVM, there is OpenJ9 and its cousin Android since version 5. PTC and Aicas remain as two well known commercial Java vendors, with AOT toolchains, alongside bare metal and real time GC support, although their focus is embedded deployments.
- mjevans 2y agoGo / golang added https://pkg.go.dev/errors https://pkg.go.dev/errors Which includes nested / stacked errors and helper functions for checking them. It doesn't implement error classes, but you can create a stacked chain of errors which achieves the same sort of 'Handle a classification of error' (anything which includes that class). Older libraries don't use these features, as far as I know. So it's sort of like the half-baked enumerate everything sort of generic functions that older stable versions (like on hacker rank) ship.
- vlovich123 2y agoI think you missed my complaint was that unlike more modern languages like Rust, Go has way too much boilerplate for error handling and not only does it not have error chaining via a `?` operator, it doesn’t even force you to check the error meaning I’m sure there’s plenty of missed error checks in production code leaving all sorts of vulnerabilities lying around. The package you linked in no way addresses what I wrote.
- Cthulhu_ 2y agoIt kinda is if you're thinking about the manual-coffee-grinder-french-press hipster who eschews automatic coffee makers. Rob Pike doesn't believe in syntax highlighting and to date the Go website / interactive editor doesn't have any. "When I was a child, I used to speak like a child, think like a child, reason like a child; when I became a man, I did away with childish things." Anyway, that's fine, I like Go and I like grinding coffee manually on occasion.
- lynx23 2y agoFunny, I have a similar analogy when it comes to mice: Small children lacking verbal communication skills can only point at things, which is the equivalnet of using a"pointing device". When they grow up, they learn to speak meaningful sentences to express themselves. Which is equvalent to learning to use the command line...
- timeon 2y ago> french-press How is that hipster? Did you mean aero-press?
- bccdee 2y agoA lot of people see anything other than a Black & Decker drip coffee pot or a Keurig pod machine as "hipster coffee," somehow. But being perceived as hipsterish is the only thing that makes something hipsterish, so they can't really be wrong.
- zelphirkalt 2y agoIf the code cannot be reached, what is the point of having it as a dependency? Does it know which part of a dependency has a vulnerability and check, if the execution reaches _that_ part? Then it would make sense.
- chucky_z 2y agoMy understanding is that the primary goal is to determine that if a program is pulling in a dependency, and only using a small part of it, to determine if that part is vulnerable or not. This allows a program owner to know if they need to do an emergency version bump in the face of a CVE or something like that. For some businesses doing emergency deployments is a massive deal.
- FiloSottile 2y ago> Does it know which part of a dependency has a vulnerability and check, if the execution reaches _that_ part? Yes, govulncheck does symbol-level reachability static analysis, and the vulndb is manually annotated with affected symbols for each vulnerability. (So glad to see a comment about this at the top, I have sometimes feared we made a mistake in designing a low-noise vulnerability scanner, because I've often seen complaints that "it doesn't work" because it doesn't show as many vulnerabilities as its more popular, less accurate alternatives.)