chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0

Forward-ports the govulncheck-action bump already on main. v1.1.0
installs a newer govulncheck that classifies GO-2026-5932 (the
unmaintained golang.org/x/crypto/openpgp advisory, no fix available)
as informational rather than an affecting vulnerability, fixing the
false-positive govulncheck failure on dev-v3 dependency PRs.

Signed-off-by: Terry Howe <terrylhowe@gmail.com>
pull/32335/head
Terry Howe 3 months ago
parent 5194383553
commit f7974839c1
No known key found for this signature in database

@ -23,6 +23,6 @@ jobs:
go-version: '${{ env.GOLANG_VERSION }}'
check-latest: true
- name: govulncheck
uses: golang/govulncheck-action@b625fbe08f3bccbe446d94fbf87fcc875a4f50ee # pin@1.0.4
uses: golang/govulncheck-action@032d45514ae346b1db93c04b0c90b841c370344f # pin@v1.1.0
with:
go-package: ./...

Loading…
Cancel
Save