663 B
663 B
Tool to find dangerous imports in go code
The tool checks for imports for a given go.mod
file that
- uses
- uses cgo
- import
The checks are performed transitively, following dependencies.
Usage of ./goosebumps:
check for imports of cgo
check for implementations of init()
check for imports of net/http/pprof
check for imports of unsafe
-exempt string
domains exempt from the search, seperated by space (default "golang.org")
-mod string
go.mod file (default "go.mod")
-modcache string
location of go mod cache (default "$GOPATH/pkg/mod")