From bffbe3f9c6b80acd69c1f68b213c9cf689e0d916 Mon Sep 17 00:00:00 2001 From: anupamme Date: Sat, 3 Oct 2026 05:09:47 +0000 Subject: [PATCH] fix: go.lang.security.audit.crypto.math_random.math-random-used security vulnerability Automated security fix generated by OrbisAI Security --- internal/utils/retries.go | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/internal/utils/retries.go b/internal/utils/retries.go index 871636e9..912816c1 100644 --- a/internal/utils/retries.go +++ b/internal/utils/retries.go @@ -4,12 +4,13 @@ package utils import ( "context" + cryptorand "crypto/rand" + "encoding/binary" "errors" "fmt" "github.com/OpenRouterTeam/go-sdk/retry" "io" "math" - "math/rand" "net" "net/http" "net/url" @@ -20,6 +21,16 @@ import ( "time" ) +// secureRandFloat64 returns a non-cryptographic-use random float64 in [0, 1) +// generated using crypto/rand instead of math/rand. +func secureRandFloat64() float64 { + var b [8]byte + if _, err := cryptorand.Read(b[:]); err != nil { + return 0.5 + } + return float64(binary.BigEndian.Uint64(b[:])) / (1 << 64) +} + // Deprecated: Use retry.BackoffStrategy instead. type BackoffStrategy = retry.BackoffStrategy @@ -252,8 +263,8 @@ func nextInterval(s *retry.BackoffStrategy, attempt int) time.Duration { interval := initialInterval * math.Pow(float64(attempt+1), exponent) - jitter := rand.Float64() * jitterFactor * interval - if rand.Float64() < 0.5 { + jitter := secureRandFloat64() * jitterFactor * interval + if secureRandFloat64() < 0.5 { jitter = -1 * jitter }