Add govulncheck scan to backend CI

Nothing in CI guarded against known vulnerabilities in the Go
dependency tree. Add a vulncheck job that runs govulncheck over the
backend module on every backend change. The version is pinned rather
than tracking latest for reproducible runs. Current tree scans clean.
This commit is contained in:
Dmitry Verkhoturov
2026-07-11 01:52:13 -05:00
committed by Umputun
parent db9d8703ef
commit d1f8cf412b
+31
View File
@@ -82,3 +82,34 @@ jobs:
working-directory: backend
env:
COVERALLS_TOKEN: ${{ secrets.GITHUB_TOKEN }}
vulncheck:
name: Vulnerability scan
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: install go
uses: actions/setup-go@v6
with:
go-version: "1.25"
# both go.sum files so the cache key covers the main and example modules scanned below
cache-dependency-path: |
backend/go.sum
backend/_example/memory_store/go.sum
- name: govulncheck
run: |
go install golang.org/x/vuln/cmd/govulncheck@v1.5.0
govulncheck ./...
(cd _example/memory_store && govulncheck ./...)
working-directory: backend
env:
# ignore the committed vendor dirs and resolve modules from the cache so
# both the main module and the nested example module scan consistently
GOFLAGS: "-mod=readonly"