commit | f718365b8d687e81808426c2c5eb05c404bd9491 | [log] [tgz] |
---|---|---|
author | Hana (Hyang-Ah) Kim <hyangah@gmail.com> | Wed Nov 23 12:31:55 2022 -0500 |
committer | Hyang-Ah Hana Kim <hyangah@gmail.com> | Wed Nov 23 23:53:30 2022 +0000 |
tree | 9e37253ad4298b48556d25765e6e70814fe78a81 | |
parent | 9519368a491771888d4c56af67a8519b48b0105f [diff] |
gopls/internal/lsp: include all vulns info to fetch_vulncheck_result In addition to the govulncheck analysis result, gopls now has its own vulnerability scanning that reports vulnerabilities on known packages in the workspace. While we are still debating on the right name for this analysis mode, let's call it 'light-weight' vuln scanning because this is less expensive than the govulncheck analysis (but with less precise result). fetch_vulncheck_result now includes the vulnerability analysis results from the light-weight vuln scanning. We distinguish the analysis source by adding Analysis field in the govulncheck.Result type. For each go.mod, if govulncheck result exists, return it. Otherwise, return the light-weight vuln scanning result if it is available in the snapshot. Change-Id: I8d53db474137cecc1138ae432207bf508c09ca6f Reviewed-on: https://go-review.googlesource.com/c/tools/+/453195 Reviewed-by: Robert Findley <rfindley@google.com> Run-TryBot: Hyang-Ah Hana Kim <hyangah@gmail.com> gopls-CI: kokoro <noreply+kokoro@google.com> TryBot-Result: Gopher Robot <gobot@golang.org>
This repository provides the golang.org/x/tools
module, comprising various tools and packages mostly for static analysis of Go programs, some of which are listed below. Use the “Go reference” link above for more information about any package.
It also contains the golang.org/x/tools/gopls
module, whose root package is a language-server protocol (LSP) server for Go. An LSP server analyses the source code of a project and responds to requests from a wide range of editors such as VSCode and Vim, allowing them to support IDE-like functionality.
Selected commands:
cmd/goimports
formats a Go program like go fmt
and additionally inserts import statements for any packages required by the file after it is edited.cmd/callgraph
prints the call graph of a Go program.cmd/digraph
is a utility for manipulating directed graphs in textual notation.cmd/stringer
generates declarations (including a String
method) for “enum” types.cmd/toolstash
is a utility to simplify working with multiple versions of the Go toolchain.These commands may be fetched with a command such as
go install golang.org/x/tools/cmd/goimports@latest
Selected packages:
go/ssa
provides a static single-assignment form (SSA) intermediate representation (IR) for Go programs, similar to a typical compiler, for use by analysis tools.
go/packages
provides a simple interface for loading, parsing, and type checking a complete Go program from source code.
go/analysis
provides a framework for modular static analysis of Go programs.
go/callgraph
provides call graphs of Go programs using a variety of algorithms with different trade-offs.
go/ast/inspector
provides an optimized means of traversing a Go parse tree for use in analysis tools.
go/cfg
provides a simple control-flow graph (CFG) for a Go function.
go/expect
reads Go source files used as test inputs and interprets special comments within them as queries or assertions for testing.
go/gcexportdata
and go/gccgoexportdata
read and write the binary files containing type information used by the standard and gccgo
compilers.
go/types/objectpath
provides a stable naming scheme for named entities (“objects”) in the go/types
API.
Numerous other packages provide more esoteric functionality.
This repository uses Gerrit for code changes. To learn how to submit changes, see https://golang.org/doc/contribute.html.
The main issue tracker for the tools repository is located at https://github.com/golang/go/issues. Prefix your issue with “x/tools/(your subdir):” in the subject line, so it is easy to find.
This repository uses prettier to format JS and CSS files.
The version of prettier
used is 1.18.2.
It is encouraged that all JS and CSS code be run through this before submitting a change. However, it is not a strict requirement enforced by CI.