Skip to content

Automate govulncheck CI #11209

Description

@williammartin

Description

To stay on top of security issues in gh we would like to periodically run govulncheck in CI and be notified of any failures.

govulncheck can be incorporated in a number of ways to cli/cli repository:

  1. Expand lint workflow to include run govulncheck, failing pull requests if a Go security vulnerability is detected

  2. Create a scheduled workflow that runs gvulncheck and uploads the resulting SARIF file to GitHub for code scanning alerts

Expected outcomes

  • gh is scanned for Go vulnerabilities as part of SDLC process
  • CLI maintainers have notification of new vulnerabilities via #cli-activity Slack channel

Activity

  1. changed the title [-]Run `govulncheck` periodically in CI[/-] [+]Automate `govulncheck` CI[/+] on Jul 3, 2025
  2. added
    coreThis issue is not accepting PRs from outside contributors
    on Jul 8, 2025
  3. self-assigned this
    on Jul 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

coreThis issue is not accepting PRs from outside contributors

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions