Skip to content

SEC-1653: remediate missing-govulncheck-workflow#2313

Merged
picatz merged 2 commits intomasterfrom
camper/missing-govulncheck-workflow-finding-govulncheck-sdk-go
Apr 27, 2026
Merged

SEC-1653: remediate missing-govulncheck-workflow#2313
picatz merged 2 commits intomasterfrom
camper/missing-govulncheck-workflow-finding-govulncheck-sdk-go

Conversation

@picatz
Copy link
Copy Markdown
Contributor

@picatz picatz commented Apr 27, 2026

🏕️ This pull request was created by camper, an automated security campaign tool.

Finding

Rulemissing-govulncheck-workflow
SeverityMEDIUM
Repositorytemporalio/sdk-go
TicketSEC-1653

Summary

  • .github/workflows/govulncheck.yml: Added a pull_request-only Govulncheck workflow with contents: read permissions, canonical ubuntu-latest runner, pinned actions/checkout and actions/setup-go SHAs (matching ci.yml comments), go-version-file: go.mod, and temporalio/public-actions/golang/govulncheck@main for differential vulnerability scanning.

Instructions

  • Approve to merge this fix
  • Request changes to trigger a new remediation attempt
  • /camper rebase — rebase onto the base branch
  • /camper close — close this PR without merging
  • /camper retry — close and retry with a new fix

@picatz picatz requested a review from a team as a code owner April 27, 2026 18:24
@picatz picatz enabled auto-merge (squash) April 27, 2026 20:13
@picatz picatz merged commit 9d32461 into master Apr 27, 2026
36 checks passed
@picatz picatz deleted the camper/missing-govulncheck-workflow-finding-govulncheck-sdk-go branch April 27, 2026 23:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants