Skip to content

build(deps): bump actions/attest-build-provenance from 8beda2b7ed98355c0e97c0a63bec38ae472e66c4 to 4d101475d8b20a2381f78447822ac1eab6504dd8 #21

build(deps): bump actions/attest-build-provenance from 8beda2b7ed98355c0e97c0a63bec38ae472e66c4 to 4d101475d8b20a2381f78447822ac1eab6504dd8

build(deps): bump actions/attest-build-provenance from 8beda2b7ed98355c0e97c0a63bec38ae472e66c4 to 4d101475d8b20a2381f78447822ac1eab6504dd8 #21

Workflow file for this run

name: Security
on:
push:
branches: [master]
pull_request:
schedule:
- cron: "17 3 * * 1"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: security-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
vulnerability-scan:
name: Go vulnerability scan
runs-on: ubuntu-24.04
steps:
- name: Check out source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: .go-version
cache: false
- name: Scan reachable code
run: go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
codeql:
name: CodeQL
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.fork == false
runs-on: ubuntu-24.04
permissions:
contents: read
security-events: write
steps:
- name: Check out source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: .go-version
cache: false
- name: Initialize CodeQL
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
languages: go
- name: Build
uses: github/codeql-action/autobuild@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
- name: Analyze
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6