checker: report a shared-schema change once, and list where else it applies #3574
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: govulncheck | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| # Optional: allow read access to pull request. Use with `only-new-issues` option. | |
| # pull-requests: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| govulncheck_job: | |
| runs-on: ubuntu-latest | |
| name: Run govulncheck | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-go@v7 | |
| with: | |
| go-version: '1.26' | |
| - name: Run govulncheck | |
| # Run govulncheck against the latest released patch of the go.mod | |
| # minor, resolved at runtime from go.dev and pulled via GOTOOLCHAIN | |
| # (the Go module proxy). This avoids two pitfalls: (1) new Go | |
| # security patches lag the actions/go-versions manifest setup-go | |
| # installs from, so a fixed-in-1.26.x advisory would otherwise fail | |
| # the check until the manifest catches up; (2) a hard-pinned | |
| # GOTOOLCHAIN needs a manual bump for every new stdlib advisory. | |
| # Tracking the go.mod minor means this also follows a go directive | |
| # bump automatically. | |
| run: | | |
| set -eo pipefail | |
| minor=$(awk '/^go /{split($2,a,"."); print a[1]"."a[2]; exit}' go.mod) | |
| latest=$(curl -fsSL "https://go.dev/dl/?mode=json&include=all" \ | |
| | python3 -c "import sys,json; vs=[r['version'] for r in json.load(sys.stdin) if r.get('stable') and r['version'].startswith('go${minor}.')]; vs.sort(key=lambda v:[int(x) for x in v[2:].split('.')]); print(vs[-1])") | |
| echo "Resolved latest go${minor} patch: ${latest}" | |
| export GOTOOLCHAIN=${latest} | |
| go install golang.org/x/vuln/cmd/govulncheck@latest | |
| govulncheck ./... |