From f7974839c19bfcb667bacf2a7f95eacb48451c38 Mon Sep 17 00:00:00 2001 From: Terry Howe Date: Sat, 11 Jul 2026 09:05:45 -0600 Subject: [PATCH] chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 Forward-ports the govulncheck-action bump already on main. v1.1.0 installs a newer govulncheck that classifies GO-2026-5932 (the unmaintained golang.org/x/crypto/openpgp advisory, no fix available) as informational rather than an affecting vulnerability, fixing the false-positive govulncheck failure on dev-v3 dependency PRs. Signed-off-by: Terry Howe --- .github/workflows/govulncheck.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/govulncheck.yml b/.github/workflows/govulncheck.yml index e4e918ad4..0ebf1a42b 100644 --- a/.github/workflows/govulncheck.yml +++ b/.github/workflows/govulncheck.yml @@ -23,6 +23,6 @@ jobs: go-version: '${{ env.GOLANG_VERSION }}' check-latest: true - name: govulncheck - uses: golang/govulncheck-action@b625fbe08f3bccbe446d94fbf87fcc875a4f50ee # pin@1.0.4 + uses: golang/govulncheck-action@032d45514ae346b1db93c04b0c90b841c370344f # pin@v1.1.0 with: go-package: ./...