</>PackageGraphPackageGraph

github.com/securego/gosec/v2

Go Modulesvv2.29.0

Go module: github.com/securego/gosec/v2

Not recommended for new projects

No — github.com/securego/gosec/v2 should not be adopted for new projects. Depended on by 2 known packages. Pulls in 1020 transitive packages (at least — some of the tree is still being crawled). This package lists no maintainer, exposes a 1020-package audit surface. No license declared — you have no explicit right to use this code.

  • CAdoption: grade C, Fair — worth a look.

    Depended on by 2 known packages.

  • AMaintenance: grade A, Excellent.

    Last published 15 days ago. 31 releases in the last 2 years.

  • FWeight: grade F, Failing.

    Pulls in 1020 transitive packages (at least — some of the tree is still being crawled).

  • DSupply chain: grade D, Poor — a real concern.

    This package lists no maintainer, exposes a 1020-package audit surface.

  • FLicense: grade F, Failing.

    No license declared — you have no explicit right to use this code.

Grades are computed deterministically from registry metadata collected by PackageGraph — downloads, dependents, publish dates, the resolved dependency tree, maintainer count, and declared licenses. No third-party scores are used.

Install cost

What you actually take on by adding github.com/securego/gosec/v2 to a project.

58
Direct dependencies

Runtime packages this one declares itself.

1K
Total installed

Distinct packages in the full runtime tree, deduplicated the way a package manager would.

6
Tree depth

Longest resolved dependency chain below this package.

Part of this dependency tree has not been crawled yet, so these figures are a lower bound rather than a final total.

Compatibility

Go
No constraint declared

Dependencies

Declared by github.com/securego/gosec/v2 vv2.29.0. Runtime dependencies are installed with the package; dev dependencies are not.

Runtime (58)

cloud.google.com/go v0.123.0cloud.google.com/go/auth v0.23.2cloud.google.com/go/compute/metadata v0.9.0github.com/BurntSushi/toml v1.6.0github.com/Masterminds/semver/v3 v3.5.0github.com/anthropics/anthropic-sdk-go v1.66.0github.com/bahlo/generic-list-go v0.2.0github.com/buger/jsonparser v1.6.1github.com/ccojocar/zxcvbn-go v1.0.4github.com/cespare/xxhash/v2 v2.3.0github.com/felixge/httpsnoop v1.1.0github.com/go-logr/logr v1.4.4github.com/go-logr/stdr v1.2.2github.com/go-task/slim-sprig/v3 v3.0.0github.com/google/go-cmp v0.7.0github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3github.com/google/s2a-go v0.1.9github.com/google/uuid v1.6.0github.com/googleapis/enterprise-certificate-proxy v0.3.20github.com/googleapis/gax-go/v2 v2.24.0github.com/gookit/color v1.6.1github.com/gorilla/websocket v1.5.3github.com/invopop/jsonschema v0.14.0github.com/lib/pq v1.12.3github.com/mozilla/tls-observatory v0.0.0-20250923143331-eef96233227egithub.com/onsi/ginkgo/v2 v2.32.1github.com/onsi/gomega v1.42.1github.com/openai/openai-go/v3 v3.52.0github.com/pb33f/ordered-map/v2 v2.3.1github.com/santhosh-tekuri/jsonschema/v6 v6.0.3github.com/standard-webhooks/standard-webhooks/libraries v0.0.1github.com/stretchr/objx v0.5.3github.com/stretchr/testify v1.12.1github.com/tidwall/gjson v1.19.0github.com/tidwall/match v1.2.0github.com/tidwall/pretty v1.2.1github.com/tidwall/sjson v1.2.5github.com/xo/terminfo v1.0.0go 1.25.0go.opentelemetry.io/auto/sdk v1.2.1go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0go.opentelemetry.io/otel v1.45.0go.opentelemetry.io/otel/metric v1.45.0go.opentelemetry.io/otel/trace v1.45.0go.yaml.in/yaml/v3 v3.0.5go.yaml.in/yaml/v4 v4.0.0-rc.6golang.org/x/crypto v0.55.0golang.org/x/mod v0.40.0golang.org/x/net v0.58.0golang.org/x/sync v0.22.0golang.org/x/sys v0.47.0golang.org/x/text v0.41.0golang.org/x/tools v0.49.0google.golang.org/api v0.293.0google.golang.org/genai v1.69.0google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688google.golang.org/grpc v1.83.1google.golang.org/protobuf v1.36.12

Used by

Popular packages that depend on github.com/securego/gosec/v2.

Relationship graph

Dependencies (left) and dependents (right) of github.com/securego/gosec/v2.

Frequently installed together

Release history

28 releases in the last two years, typically about 17 days apart.

Recent versions of github.com/securego/gosec/v2
VersionPublishedLicense
v2.29.0latest15 days ago
v2.28.01 month ago
v2.27.13 months ago
v2.27.03 months ago
v2.26.14 months ago
v2.26.04 months ago
v2.25.05 months ago
v2.24.76 months ago
v2.24.66 months ago
v2.24.56 months ago
v2.24.46 months ago
v2.24.26 months ago
v2.24.36 months ago
v2.24.16 months ago
v2.24.06 months ago

Overview

github.com/securego/gosec/v2 is an Go Modules package that go module: github.com/securego/gosec/v2. It has 2 known dependents in the graph. The latest version is v2.29.0.

Who should use it

Teams working in the Go Modules ecosystem who need go module: github.com/securego/gosec/v2 and value a focused solution.

When not to use it

Consider an alternative if you need to minimize your dependency tree, or if a more actively-maintained option better fits your Go Modules stack.

Pros

  • Actively published to the registry.

Cons

  • Large dependency tree (58 direct dependencies) increases install size and audit surface.
  • No license detected — review usage terms before adopting.

Auto-generated from collected registry metadata. No external claims are inferred.

Frequently asked questions

Should I use github.com/securego/gosec/v2?

No — github.com/securego/gosec/v2 should not be adopted for new projects. Depended on by 2 known packages. Pulls in 1020 transitive packages (at least — some of the tree is still being crawled). This package lists no maintainer, exposes a 1020-package audit surface. No license declared — you have no explicit right to use this code.

How do I install github.com/securego/gosec/v2?

Run `go get github.com/securego/gosec/v2` to add github.com/securego/gosec/v2 to your Go Modules project.

How many dependencies does github.com/securego/gosec/v2 have?

github.com/securego/gosec/v2 declares 58 direct dependencies and pulls in 1020 packages in total once its runtime tree is resolved.

What license is github.com/securego/gosec/v2 released under?

No license was detected in github.com/securego/gosec/v2's metadata; review the repository before use.

How popular is github.com/securego/gosec/v2?

Go Modules does not publish download counts. Within PackageGraph's crawl, 2 known packages depend on github.com/securego/gosec/v2.

Is github.com/securego/gosec/v2 still maintained?

The most recent release of github.com/securego/gosec/v2 (vv2.29.0) was published 15 days ago.