feat: add flag -exclude-analyzers #1420
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This adds a new flag,
-exclude-analyzers, which excludes allAnalyzer-based rules.Alongside #1419, this makes it convenient to run a slightly slimmed-down, substantially faster version of Gosec. It's not very difficult to exclude these rules yourself, except:
Analyzer-based rules added in future updates to Gosec could lead to significant, unexpected performance regressions, if those users fail to add the new rules to the-excludelist