Merge pull request #17550 from ivanvc/release-3.5-add-govuln-github-workflow

[3.5] Add govuln GitHub workflow
This commit is contained in:
Benjamin Wang 2024-03-08 17:00:56 +00:00 committed by GitHub
commit d0a02813d4
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

19
.github/workflows/govuln.yaml vendored Normal file
View File

@ -0,0 +1,19 @@
---
name: Go Vulnerability Checker
on: [push, pull_request]
permissions: read-all
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- id: goversion
run: echo "goversion=$(cat .go-version)" >> "$GITHUB_OUTPUT"
- uses: actions/setup-go@0c52d547c9bc32b1aa3301fd7a9cb496313a4491 # v5.0.0
with:
go-version: ${{ steps.goversion.outputs.goversion }}
- run: date
- run: |
set -euo pipefail
go install golang.org/x/vuln/cmd/govulncheck@latest && govulncheck ./...