Skip to content

Commit

Permalink
Bump CI govulncheck to v1.0.0 (#414)
Browse files Browse the repository at this point in the history
* Bump CI govulncheck to v1.0.0.
* Remove scheduled trigger (move it to private repo).
  • Loading branch information
fxamacker authored Jul 15, 2023
1 parent 48c838c commit 8864562
Showing 1 changed file with 3 additions and 7 deletions.
10 changes: 3 additions & 7 deletions .github/workflows/govulncheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,6 @@ permissions: {}

on:
workflow_dispatch:
schedule:
# Run at least once daily because vulnerability database might be updated.
- cron: '30 15 * * *'
pull_request:
paths:
- '**'
Expand Down Expand Up @@ -45,7 +42,6 @@ jobs:
go-version: 1.20.x
check-latest: true
- name: Install latest from golang.org
run: go install golang.org/x/vuln/cmd/govulncheck@b43f5afc876383b2adc0ec0d3ff1998fe58eeda0 # v0.1.0
- name: Run govulncheck
# Use -v flag to print a full call stack for each vulnerability found.
run: govulncheck -v ./...
run: go install golang.org/x/vuln/cmd/govulncheck@f69de671333b611ab6b6f21f8ff0ab53f6d96c61 # v1.0.0
- name: Run govulncheck
run: govulncheck -show=traces ./...

0 comments on commit 8864562

Please sign in to comment.