Skip to content

fix(analyzer): harden method-value dataflow - #87

Open
lasiar wants to merge 1 commit into
mainfrom
update
Open

lasiar wants to merge 1 commit into
mainfrom
update

Conversation

@lasiar

@lasiar lasiar commented Feb 6, 2026

Copy link
Copy Markdown
Owner

Rework analyzer internals to resolve method-value calls on http.Header reliably across assignment chains and enclosing function scopes.

  • switch traversal to inspector.WithStack and pass explicit call context
  • replace Obj.Decl-based method-value lookup with state tracking over AssignStmt/ValueSpec up to the call position
  • add safer resolver/helpers for receiver/method detection, type-cast unwrapping, exclusions lookup, and inspect result validation
  • improve literal/const diagnostic wording and add focused tests for analyzer internals, configure parsing, and initialismer template mapping
  • refresh tooling baseline (Go 1.25, x/tools 0.41, testify 1.11.1), migrate golangci-lint config to v2, and align CI/make targets accordingly

@lasiar
lasiar force-pushed the update branch 3 times, most recently from dcf8741 to 1980c4b Compare February 6, 2026 19:12
Rework analyzer internals to resolve method-value calls on http.Header
reliably across assignment chains and enclosing function scopes.

- switch traversal to inspector.WithStack and pass explicit call context
- replace Obj.Decl-based method-value lookup with state tracking over
  AssignStmt/ValueSpec up to the call position
- add safer resolver/helpers for receiver/method detection, type-cast
  unwrapping, exclusions lookup, and inspect result validation
- improve literal/const diagnostic wording and add focused tests for
  analyzer internals, configure parsing, and initialismer template mapping
- refresh tooling baseline (Go 1.25, x/tools 0.41, testify 1.11.1), migrate
  golangci-lint config to v2, and align CI/make targets accordingly
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant