XR007

ResourcesExtra · tfsproutxFixable with -fix

check for os/exec.Command usage

The XR007 analyzer reports usage of the os/exec.Command() function. Providers that are using Go language based SDKs likely want to prevent any execution of other binaries for various reasons such as security and unexpected requirements (e.g. tool installation outside Terraform).

Examples

var sneaky = exec.Command

sneaky("evilprogram")

exec.Command("evilprogram")
// Not present :)

Ignoring reports

Singular reports can be ignored by adding a //lintignore:XR007 Go code comment at the end of the offending line or on the line immediately preceding, e.g.

//lintignore:XR007
exec.Command("evilprogram")

This page is generated from xpasses/XR007/README.md, which lives beside the analyzer.