Upgrade to Pro — share decks privately, control downloads, hide ads and more …

脆弱性対応、どこで線を引くか

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.

 脆弱性対応、どこで線を引くか

2026/06/17 Go Connect #14

Avatar for ryoji miyamoto

ryoji miyamoto

June 17, 2026

More Decks by ryoji miyamoto

Other Decks in Technology

Transcript

  1. govulncheck は Severity を出さない Trivy などは Critical / High /

    Medium でラベリング govulncheck はラベルなし 判断は開発者が持つ、という Go らしい設計思想 Trivy
  2. govulncheck の出力例 検出あり 検出なし === Symbol Results === Vulnerability #1:

    GO-2025-XXXX Found in: golang.org/x/[email protected] Fixed in: golang.org/x/[email protected] Example traces found: #1: internal/api/handler.go:42 === Symbol Results === No vulnerabilities found.