Stacked on !254. Clears the remaining 74 findings — go:S4036, 63% of
the dashboard.
The practical reason is the one you and I agreed on: a dashboard that is mostly permanent noise is one nobody reads, which is the state a scan exists to avoid. But it earns its place on its own terms:
- A missing tool is one legible failure at start-up.
gitbaydcallstoolpath.Verify()before loading config, instead of failing opaquely on whichever request first needed git. - The command a daemon runs is fixed for its lifetime, decided from
the environment it started with. Both daemons run under systemd with a
root-owned PATH and read-only
/usr, so the search was never attacker-influenced in a shipped configuration — but a spawn that cannot be redirected is one fewer thing to reason about. - The lookup leaves the hot path. A repository page spawns several git processes and each was searching PATH from scratch.
Note it covers ssh as well as git — the 74 weren't all git;
cmd/gitbay/ssh.go and the runner contribute ssh invocations.
An unresolvable tool falls back to the bare name, so anything running
before Verify fails exactly as it did.
Production code only. My first pass also rewrote 15 test files; all 74 findings are in production code, so that was churn and I reverted it.
Given this touches every git and ssh invocation in the daemon, I ran the
full e2e suite rather than a subset: ok 1092.547s.
Closes #153
retargeted from sonar-a11y-config to main: !254 merged
2026-09-05 00:02 UTC