Files
keywarden/.gitea/workflows/security-scan.yml
scriptos eb1f4e0738
All checks were successful
PR Tests / Lint, Build & Test (pull_request) Successful in 6m7s
Security Scan / Go Vulnerability Check (pull_request) Successful in 5m33s
fix: bump Go from 1.26.1 to 1.26.2 to resolve stdlib vulnerabilities
2026-04-08 20:09:40 +02:00

28 lines
626 B
YAML

# Keywarden CI - Security Scan
# Checks for known vulnerabilities in Go dependencies on PRs
name: Security Scan
on:
pull_request:
branches: [master]
jobs:
govulncheck:
name: Go Vulnerability Check
runs-on: ubuntu-latest
container:
image: golang:1.26.2-alpine
steps:
- name: Install dependencies
run: apk add --no-cache git gcc musl-dev sqlite-dev nodejs
- name: Checkout code
uses: actions/checkout@v4
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Run govulncheck
run: govulncheck ./...