{"repo":"Templum/govulncheck-action","free":true,"listed":false,"github":"https://github.com/Templum/govulncheck-action","clone":"git clone https://github.com/Templum/govulncheck-action.git","description":"This action uses govulncheck to perform a scan of the code, afterwards it will parse the output and transform it into an Sarif Report, which will be uploaded to Github using the code-scanning API.","language":"Go","stars":22,"topics":["code-scanner","github-actions","golang-tools","sarif-report","security-tools","go","golang"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Golang Vulncheck This action uses govulncheck to perform a scan of the code, afterwards it will parse the output and transform it into an Sarif Report, which will be uploaded to Github using the code-scanning API. Please note this requires write-permission for security events . The result should then be visible within the security-tab. By default this action won't exit with a failure if a vulnerability was found, but it can be configured this way. :information source: Limitations of govulncheck :information source: For a full list of currently known limitations please head over to here. Listed below are an important overview. Govulncheck analyzes function pointer and interface calls conservatively, which may result in false positives or inaccurate call stacks in some cases. Calls to functions made using package reflect are not visible to static analysis. Vulnerable code reachable only through those calls will not be reported. There is no support for silencing vulnerability findings. :books: Useful links & resources on govulncheck :books: Official Package Documentation: Link Introduction Blogpost: Link Usage Where can I find the scan results of this action ? Please be aware there will be no direct output to the console, all found vulnerabilities will be reported to Github via an Sarif Report. Therefore all findings should be located in the Security -Tab under the Code Scanning -Section. Example Workflows This configuration uses a different version of go (1.18) scans ./... and ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Templum","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Templum/govulncheck-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}