Repository navigation
build(deps): bump reviewdog/action-actionlint from 1.77.0 to 1.79.1 #31
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: govulncheck | |
| # Vulnerability scanning against the official Go vulnerability database | |
| # (https://vuln.go.dev). gosec in golangci-lint looks for insecure code this | |
| # repository writes; govulncheck answers a different question: whether a known | |
| # advisory in the standard library or in a dependency is reachable from this | |
| # repository's own call graph. | |
| # | |
| # The database changes every day, so a scan that passed at merge time can fail | |
| # tomorrow without a line of this repository changing. The pull_request/push | |
| # legs catch a newly added dependency; the schedule catches a newly published | |
| # advisory against the dependencies already in go.sum. | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| schedule: | |
| - cron: "0 4 * * *" | |
| permissions: | |
| contents: read | |
| jobs: | |
| govulncheck: | |
| name: govulncheck (Go ${{ matrix.go }}) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| # Every Go line this repository supports: a standard-library advisory is | |
| # fixed in a specific patch of a specific minor, so an advisory fixed in the | |
| # newest Go can still be live for someone building with the minimum. | |
| # Keep the first entry equal to the go directive in go.mod. | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| go: | |
| - "1.26.6" | |
| - "stable" | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version: ${{ matrix.go }} | |
| check-latest: true | |
| # Pinned so a scanner release cannot change the verdict on its own. The | |
| # advisory database is intentionally not pinned. | |
| - name: Install govulncheck | |
| run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0 | |
| # ACCEPTED lists advisories this repository is known to reach and has | |
| # defended against on its own side, one ID each, with why, which test holds | |
| # the defense, and when to remove it. Leave it empty when there are none. | |
| # Any other reachable advisory fails the job and prints the text report. | |
| # pipefail and the record-count check keep a failed or empty scan from | |
| # reading as "nothing found": the default run shell does not set pipefail, | |
| # so a jq error would otherwise be hidden behind sort. | |
| - name: Scan the module | |
| env: | |
| ACCEPTED: "" | |
| run: | | |
| set -o pipefail | |
| govulncheck -format json ./... > "$RUNNER_TEMP/govulncheck.json" | |
| jq -e -s 'length > 0' "$RUNNER_TEMP/govulncheck.json" > /dev/null | |
| jq -r 'select(.finding != null and (.finding.trace[0].function // "") != "") | .finding.osv' \ | |
| "$RUNNER_TEMP/govulncheck.json" | sort -u > "$RUNNER_TEMP/called.txt" | |
| tr ' ' '\n' <<< "$ACCEPTED" | sed '/^$/d' > "$RUNNER_TEMP/accepted.txt" | |
| if grep -vxF -f "$RUNNER_TEMP/accepted.txt" "$RUNNER_TEMP/called.txt"; then | |
| echo "::error::govulncheck found an advisory that is not in ACCEPTED" | |
| govulncheck ./... | |
| exit 1 | |
| fi |