From f682c28103f9b7159f3244092aab8b5b64cd3838 Mon Sep 17 00:00:00 2001 From: Eddie Torres Date: Mon, 16 Oct 2023 17:09:58 +0000 Subject: [PATCH] Add govulncheck and dependency-review to CI workflow Signed-off-by: Eddie Torres --- .github/workflows/dependency-review.yaml | 15 +++++++++++++++ .github/workflows/govulncheck.yaml | 14 ++++++++++++++ 2 files changed, 29 insertions(+) create mode 100644 .github/workflows/dependency-review.yaml create mode 100644 .github/workflows/govulncheck.yaml diff --git a/.github/workflows/dependency-review.yaml b/.github/workflows/dependency-review.yaml new file mode 100644 index 0000000000..5ab21d4cb0 --- /dev/null +++ b/.github/workflows/dependency-review.yaml @@ -0,0 +1,15 @@ +name: 'Dependency Review' +on: [pull_request] + +permissions: + contents: read + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - name: 'Checkout Repository' + uses: actions/checkout@v4 + + - name: 'Dependency Review' + uses: actions/dependency-review-action@v3 diff --git a/.github/workflows/govulncheck.yaml b/.github/workflows/govulncheck.yaml new file mode 100644 index 0000000000..b56c17a484 --- /dev/null +++ b/.github/workflows/govulncheck.yaml @@ -0,0 +1,14 @@ +name: 'govulncheck' +on: [pull_request] + +jobs: + govulncheck: + runs-on: ubuntu-latest + steps: + - name: 'Checkout Repository' + uses: actions/checkout@v4 + + - name: 'Run govulncheck' + uses: golang/govulncheck-action@v1 + with: + go-version-file: 'go.mod'