fix(ci): pin gosec and govulncheck-action to concrete version tags
This commit is contained in:
@@ -49,12 +49,12 @@ jobs:
|
|||||||
go mod verify
|
go mod verify
|
||||||
|
|
||||||
- name: Run gosec security analysis
|
- name: Run gosec security analysis
|
||||||
uses: securego/gosec@v2
|
uses: securego/gosec@v2.22.4
|
||||||
with:
|
with:
|
||||||
args: ./...
|
args: ./...
|
||||||
|
|
||||||
- name: Run govulncheck
|
- name: Run govulncheck
|
||||||
uses: golang/govulncheck-action@v1
|
uses: golang/govulncheck-action@v1.1.4
|
||||||
with:
|
with:
|
||||||
go-package: ./...
|
go-package: ./...
|
||||||
cache: true
|
cache: true
|
||||||
|
|||||||
@@ -45,12 +45,12 @@ jobs:
|
|||||||
go mod verify
|
go mod verify
|
||||||
|
|
||||||
- name: Run gosec security analysis
|
- name: Run gosec security analysis
|
||||||
uses: securego/gosec@v2
|
uses: securego/gosec@v2.22.4
|
||||||
with:
|
with:
|
||||||
args: ./...
|
args: ./...
|
||||||
|
|
||||||
- name: Run govulncheck
|
- name: Run govulncheck
|
||||||
uses: golang/govulncheck-action@v1
|
uses: golang/govulncheck-action@v1.1.4
|
||||||
with:
|
with:
|
||||||
go-package: ./...
|
go-package: ./...
|
||||||
cache: true
|
cache: true
|
||||||
|
|||||||
Reference in New Issue
Block a user