Skip to content

build(deps): bump reviewdog/action-actionlint from 1.77.0 to 1.79.1 #31

build(deps): bump reviewdog/action-actionlint from 1.77.0 to 1.79.1

build(deps): bump reviewdog/action-actionlint from 1.77.0 to 1.79.1 #31

Workflow file for this run

name: govulncheck
# Vulnerability scanning against the official Go vulnerability database
# (https://vuln.go.dev). gosec in golangci-lint looks for insecure code this
# repository writes; govulncheck answers a different question: whether a known
# advisory in the standard library or in a dependency is reachable from this
# repository's own call graph.
#
# The database changes every day, so a scan that passed at merge time can fail
# tomorrow without a line of this repository changing. The pull_request/push
# legs catch a newly added dependency; the schedule catches a newly published
# advisory against the dependencies already in go.sum.
on:
workflow_dispatch:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: "0 4 * * *"
permissions:
contents: read
jobs:
govulncheck:
name: govulncheck (Go ${{ matrix.go }})
runs-on: ubuntu-latest
timeout-minutes: 15
# Every Go line this repository supports: a standard-library advisory is
# fixed in a specific patch of a specific minor, so an advisory fixed in the
# newest Go can still be live for someone building with the minimum.
# Keep the first entry equal to the go directive in go.mod.
strategy:
fail-fast: false
matrix:
go:
- "1.26.6"
- "stable"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: ${{ matrix.go }}
check-latest: true
# Pinned so a scanner release cannot change the verdict on its own. The
# advisory database is intentionally not pinned.
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0
# ACCEPTED lists advisories this repository is known to reach and has
# defended against on its own side, one ID each, with why, which test holds
# the defense, and when to remove it. Leave it empty when there are none.
# Any other reachable advisory fails the job and prints the text report.
# pipefail and the record-count check keep a failed or empty scan from
# reading as "nothing found": the default run shell does not set pipefail,
# so a jq error would otherwise be hidden behind sort.
- name: Scan the module
env:
ACCEPTED: ""
run: |
set -o pipefail
govulncheck -format json ./... > "$RUNNER_TEMP/govulncheck.json"
jq -e -s 'length > 0' "$RUNNER_TEMP/govulncheck.json" > /dev/null
jq -r 'select(.finding != null and (.finding.trace[0].function // "") != "") | .finding.osv' \
"$RUNNER_TEMP/govulncheck.json" | sort -u > "$RUNNER_TEMP/called.txt"
tr ' ' '\n' <<< "$ACCEPTED" | sed '/^$/d' > "$RUNNER_TEMP/accepted.txt"
if grep -vxF -f "$RUNNER_TEMP/accepted.txt" "$RUNNER_TEMP/called.txt"; then
echo "::error::govulncheck found an advisory that is not in ACCEPTED"
govulncheck ./...
exit 1
fi