vulncheck: include more references to functions

Includes references to functions in operators of CallInstructions
when forward slicing for VTA.

Additionally avoids allocating slices of callees when forward
slicing. On net/http benchmark overall makes callgraph construction
5% faster and consume 2% less memory.

Change-Id: I52c775c397fb8ae06d6129957fd27d2516b8e740
Run-TryBot: Tim King <>
Reviewed-by: Zvonimir Pavlinovic <>
TryBot-Result: Gopher Robot <>
3 files changed
tree: dc8a8f3de89bdc385dd397ddfb91bc50a5fcd4d1
  1. client/
  2. cmd/
  3. devtools/
  4. doc/
  5. exp/
  6. internal/
  7. osv/
  8. vulncheck/
  9. .gitignore
  10. all_test.go
  11. checks.bash
  13. go.mod
  14. go.sum
  18. tools_test.go

Go Vulnerability Management

Go Reference

This repository contains packages for accessing and analyzing data from the Go Vulnerability Database. It contains the following:

  • Package client: a client for interacting with the Go vulnerability database
  • Package vulncheck: an API for detecting vulnerabilities in Go packages
  • Command govulncheck: a CLI for detecting vulnerabilities in Go packages

Check out for more information about the Go vulnerability management system.

Privacy Policy

The privacy policy for govulncheck can be found at


Unless otherwise noted, the Go source files are distributed under the BSD-style license found in the LICENSE file.

Database entries available at are distributed under the terms of the CC-BY 4.0 license.