Skip to content

Re-enable govulncheck for PRs #4935

@swiatekm

Description

@swiatekm

govulncheck can block all PRs due to new entries being added to the vulndb, without any connection to the PR changes. We should scope it down significantly, ideally to only run on changes which add new dependencies. Independently, it should run on a schedule on main and publish its findings to GitHub's Security panel.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions