Skip to content

ci: run govulncheck on both modules - #82

Merged
FumingPower3925 merged 1 commit into
mainfrom
ci/426-govulncheck
Sep 19, 2026
Merged

FumingPower3925 merged 1 commit into
mainfrom
ci/426-govulncheck

Conversation

@FumingPower3925

Copy link
Copy Markdown
Contributor

Summary

Adds a Vulnerability Check job that runs govulncheck ./... on both Go modules: the root module and internal/integrationtest/testserver, which pins its own celeris. Until now only celeris ran govulncheck.

Refs goceleris/celeris#426. The docs half of that issue is already done: docs has Dependabot for bun and GitHub Actions, and an astro check gate. The probatorium half follows after goceleris/probatorium#400.

Details

  • govulncheck fails (exit 3) only when this code can reach a vulnerable symbol. A vulnerable module that is required but whose vulnerable code is never called is reported without failing the job.
  • The scanner is pinned to golang.org/x/vuln/cmd/govulncheck@v1.8.0, the current release, instead of @latest. A new scanner therefore cannot change the verdict unannounced. The vulnerability database is fetched live from vuln.go.dev on every run.
  • The action SHAs and the Go version match the other jobs in this file.

Proof that the job can fail

The job's two run steps were extracted verbatim from this ci.yml with PyYAML and run with bash --noprofile --norc -eo pipefail in each step's working directory, using govulncheck v1.8.0, against three copies of the tree:

arm root step testserver step
this branch, unedited exit 0 exit 0
root module + a package calling jwt.MapClaims.VerifyAudience (github.com/dgrijalva/jwt-go v3.2.0, GO-2020-0017, no fixed version) exit 3, reports GO-2020-0017 exit 0
the same control in the testserver module exit 0 exit 3, reports GO-2020-0017

So each step catches a reachable vulnerability in its own module, and passes on the unedited tree. CI on this PR shows the unedited result on the runner.

At main (ea3c3b9), both modules scan clean: "No vulnerabilities found."

Only celeris ran govulncheck. loadgen is a published module and its
testserver helper pins its own celeris, so both are scanned. govulncheck
fails only when this code can reach a vulnerable symbol. The scanner is
pinned to v1.8.0; the vulnerability database is fetched live on every run.
@FumingPower3925
FumingPower3925 merged commit 165fc8a into main Sep 19, 2026
7 checks passed
@FumingPower3925
FumingPower3925 deleted the ci/426-govulncheck branch September 19, 2026 06:26
@FumingPower3925 FumingPower3925 mentioned this pull request Sep 27, 2026
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant