Skip to content

Fix govulncheck failures (9 CVEs in Go dependencies) #6600

@mohammedfirdouss

Description

@mohammedfirdouss

PR #6435 adds govulncheck CI. It correctly detects these pre-existing vulnerabilities:

  • GO-2025-4007, GO-2025-4008, GO-2025-4009, GO-2025-4010, GO-2025-4011
  • GO-2025-4012, GO-2025-4013, GO-2025-4155, GO-2026-4603
    16 vulnerabilities from Go stdlib + 1 module affect code paths.

Failing modules

  • ./tool/actions-plan-preview
  • ./tool/actions-gh-release
  • ./pkg/app/pipedv1/plugin/* (multiple)
  • Root module (.)

Main failures:

Full workflow run: https://github.com/pipe-cd/pipecd/actions/runs/23225026408

Fix approach

  • Update Go version (if stdlib-related)
  • Run go get -u on affected deps
  • Re-run govulncheck ./... locally
  • Confirm all pass before merge

cc @Warashi @khanhtc1202

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions