diff --git a/pkg/plugins/manager/installer/installer.go b/pkg/plugins/manager/installer/installer.go index dac982a2f8e..3d21246e008 100644 --- a/pkg/plugins/manager/installer/installer.go +++ b/pkg/plugins/manager/installer/installer.go @@ -527,14 +527,16 @@ func (i *Installer) extractFiles(archiveFile string, pluginID string, dest strin } r, err := zip.OpenReader(archiveFile) + if err != nil { + return err + } + defer func() { if err := r.Close(); err != nil { i.log.Warn("failed to close zip file", "err", err) } }() - if err != nil { - return err - } + for _, zf := range r.File { // We can ignore gosec G305 here since we check for the ZipSlip vulnerability below // nolint:gosec