-
Notifications
You must be signed in to change notification settings - Fork 3k
Closed
Labels
Type: MaintenanceUpdating phrasing or wording to make things clearer or removing ambiguity.Updating phrasing or wording to make things clearer or removing ambiguity.
Milestone
Description
Describe your feature request
Add two new features:
- Dependabot Update: A new security group in the
gomodecosystem focusing on security updates for Go modules. - Govulncheck Workflow: A GitHub Action to automatically run
govulncheckevery week -> uploads the results to GitHub in SARIF format.
Describe the use case of the feature
-
Dependabot Security Updates:
- Automates critical security patches for Go modules, so we don’t have to worry about them manually (example: stop using deprecated mholt/archiver #5951).
-
Govulncheck Scanning:
- Finds vulnerabilities early, so we can fix them before they escalate into serious issues.
- Uploads results directly into GitHub’s security dashboard, making it easy to review and handle problems.
Describe alternatives you've considered
No response
Additional context
The Dependabot change is just for security updates. Both features reduce technical debt: Dependabot handles security updates automatically, and govulncheck ensures our dependencies are secure w/o extra manual effort.
Metadata
Metadata
Assignees
Labels
Type: MaintenanceUpdating phrasing or wording to make things clearer or removing ambiguity.Updating phrasing or wording to make things clearer or removing ambiguity.