Skip to content

checker: report a shared-schema change once, and list where else it applies #3574

checker: report a shared-schema change once, and list where else it applies

checker: report a shared-schema change once, and list where else it applies #3574

Workflow file for this run

name: govulncheck
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
# Optional: allow read access to pull request. Use with `only-new-issues` option.
# pull-requests: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
govulncheck_job:
runs-on: ubuntu-latest
name: Run govulncheck
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version: '1.26'
- name: Run govulncheck
# Run govulncheck against the latest released patch of the go.mod
# minor, resolved at runtime from go.dev and pulled via GOTOOLCHAIN
# (the Go module proxy). This avoids two pitfalls: (1) new Go
# security patches lag the actions/go-versions manifest setup-go
# installs from, so a fixed-in-1.26.x advisory would otherwise fail
# the check until the manifest catches up; (2) a hard-pinned
# GOTOOLCHAIN needs a manual bump for every new stdlib advisory.
# Tracking the go.mod minor means this also follows a go directive
# bump automatically.
run: |
set -eo pipefail
minor=$(awk '/^go /{split($2,a,"."); print a[1]"."a[2]; exit}' go.mod)
latest=$(curl -fsSL "https://go.dev/dl/?mode=json&include=all" \
| python3 -c "import sys,json; vs=[r['version'] for r in json.load(sys.stdin) if r.get('stable') and r['version'].startswith('go${minor}.')]; vs.sort(key=lambda v:[int(x) for x in v[2:].split('.')]); print(vs[-1])")
echo "Resolved latest go${minor} patch: ${latest}"
export GOTOOLCHAIN=${latest}
go install golang.org/x/vuln/cmd/govulncheck@latest
govulncheck ./...