fix(ci): run gosec via go install to use setup-go toolchain
This commit is contained in:
@@ -49,16 +49,13 @@ jobs:
|
|||||||
go mod verify
|
go mod verify
|
||||||
|
|
||||||
- name: Run gosec security analysis
|
- name: Run gosec security analysis
|
||||||
uses: securego/gosec@v2.22.4
|
run: |
|
||||||
env:
|
set -euo pipefail
|
||||||
GOTOOLCHAIN: auto
|
go install github.com/securego/gosec/v2/cmd/gosec@v2.22.4
|
||||||
with:
|
gosec ./...
|
||||||
args: ./...
|
|
||||||
|
|
||||||
- name: Run govulncheck
|
- name: Run govulncheck
|
||||||
uses: golang/govulncheck-action@v1.0.4
|
uses: golang/govulncheck-action@v1.0.4
|
||||||
env:
|
|
||||||
GOTOOLCHAIN: auto
|
|
||||||
with:
|
with:
|
||||||
go-package: ./...
|
go-package: ./...
|
||||||
cache: true
|
cache: true
|
||||||
|
|||||||
@@ -45,9 +45,10 @@ jobs:
|
|||||||
go mod verify
|
go mod verify
|
||||||
|
|
||||||
- name: Run gosec security analysis
|
- name: Run gosec security analysis
|
||||||
uses: securego/gosec@v2.22.4
|
run: |
|
||||||
with:
|
set -euo pipefail
|
||||||
args: ./...
|
go install github.com/securego/gosec/v2/cmd/gosec@v2.22.4
|
||||||
|
gosec ./...
|
||||||
|
|
||||||
- name: Run govulncheck
|
- name: Run govulncheck
|
||||||
uses: golang/govulncheck-action@v1.0.4
|
uses: golang/govulncheck-action@v1.0.4
|
||||||
|
|||||||
Reference in New Issue
Block a user