From a69938e50b63ae468a07d8f435e91e92591471ac Mon Sep 17 00:00:00 2001 From: ford220102 <138443348+ford220102@users.noreply.github.com> Date: Tue, 14 Jul 2026 23:13:44 +0200 Subject: [PATCH 1/2] fix(security): replace MD5 with SHA-256 for appstore workdir hashing Resolves SonarCloud security hotspot go:S4790 (weak hash algorithm). MD5 was used in WorkDir() only to derive a cache directory name from the appstore URL path - not for any security-sensitive purpose - but using a weak hash still triggers static analysis warnings. Switched to SHA-256 to close the hotspot with no functional changes. --- service/appstore.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/service/appstore.go b/service/appstore.go index a860cc78..626692c7 100644 --- a/service/appstore.go +++ b/service/appstore.go @@ -1,7 +1,7 @@ package service import ( - "crypto/md5" // nolint: gosec + "crypto/sha256" "fmt" "io/fs" "net/http" @@ -242,7 +242,7 @@ func (s *appStore) WorkDir() (string, error) { appstoreKey := strings.ToLower(parsedURL.Path) - hash := fmt.Sprintf("%x", md5.Sum([]byte(appstoreKey))) //nolint: gosec + hash := fmt.Sprintf("%x", sha256.Sum256([]byte(appstoreKey))) return filepath.Join(config.AppInfo.AppStorePath, parsedURL.Host, hash), nil } From 0f3873fcaa90506b5d47d0bb0371841c777684ab Mon Sep 17 00:00:00 2001 From: ford220102 <138443348+ford220102@users.noreply.github.com> Date: Tue, 14 Jul 2026 23:18:10 +0200 Subject: [PATCH 2/2] fix: close HTTP response body after HEAD request in UpdateCatalog Resolves SonarCloud reliability bug (http-resource-leak, L83). http.Head() response body was never closed on the success path, leaking the underlying connection. Added defer res.Body.Close() immediately after the error check. --- service/appstore.go | 2 ++ 1 file changed, 2 insertions(+) diff --git a/service/appstore.go b/service/appstore.go index 626692c7..31b9be2b 100644 --- a/service/appstore.go +++ b/service/appstore.go @@ -84,6 +84,8 @@ func (s *appStore) UpdateCatalog() error { if err != nil { return err } + defer res.Body.Close() + if res.StatusCode != http.StatusOK { return fmt.Errorf("failed to get appstore size, status code: %d", res.StatusCode) }