diff --git a/.github/workflows/build-and-test-windows.yml b/.github/workflows/build-and-test-windows.yml index 996ba335bdcc..58c87e9f960b 100644 --- a/.github/workflows/build-and-test-windows.yml +++ b/.github/workflows/build-and-test-windows.yml @@ -52,7 +52,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 - name: Cache Go id: go-mod-cache uses: actions/cache@v3 diff --git a/.github/workflows/build-and-test.yml b/.github/workflows/build-and-test.yml index f642ec837f9c..d064aab0f585 100644 --- a/.github/workflows/build-and-test.yml +++ b/.github/workflows/build-and-test.yml @@ -130,6 +130,29 @@ jobs: echo "One or more matrix jobs failed." false fi + govulncheck: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Checkout Repo + uses: actions/checkout@v3 + - name: Setup Go + uses: actions/setup-go@v3 + with: + go-version: ~1.19.8 + - name: Cache Go + id: go-cache + uses: actions/cache@v3 + with: + path: | + ~/go/bin + ~/go/pkg/mod + key: go-cache-${{ runner.os }}-${{ hashFiles('**/go.sum') }} + - name: Install Tools + if: steps.go-cache.outputs.cache-hit != 'true' + run: make install-tools + - name: Run `govulncheck` + run: make govulncheck checks: runs-on: ubuntu-latest needs: [setup-environment] diff --git a/.github/workflows/changelog.yml b/.github/workflows/changelog.yml index 1fab9a502ff9..81a9871c79f8 100644 --- a/.github/workflows/changelog.yml +++ b/.github/workflows/changelog.yml @@ -33,7 +33,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 - name: Cache Go id: go-cache uses: actions/cache@v3 diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index c43b8c88f531..716beb259359 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -26,7 +26,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/create-dependabot-pr.yml b/.github/workflows/create-dependabot-pr.yml index a6e6f1e25d41..5ee8e9042607 100644 --- a/.github/workflows/create-dependabot-pr.yml +++ b/.github/workflows/create-dependabot-pr.yml @@ -11,7 +11,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 - name: Run dependabot-pr.sh run: ./.github/workflows/scripts/dependabot-pr.sh env: diff --git a/.github/workflows/prepare-release.yml b/.github/workflows/prepare-release.yml index 8db877c7d6ff..d9c0a181eab6 100644 --- a/.github/workflows/prepare-release.yml +++ b/.github/workflows/prepare-release.yml @@ -27,7 +27,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 - name: Prepare release for contrib working-directory: opentelemetry-collector-contrib env: diff --git a/.github/workflows/prometheus-compliance-tests.yml b/.github/workflows/prometheus-compliance-tests.yml index 598ca47d7099..09709d78e294 100644 --- a/.github/workflows/prometheus-compliance-tests.yml +++ b/.github/workflows/prometheus-compliance-tests.yml @@ -32,7 +32,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v3 with: - go-version: ~1.19.7 + go-version: ~1.19.8 - name: Cache Go id: go-cache uses: actions/cache@v3