[govulncheck] Pre-submit Prow Job for govulncheck
#99
Labels
area/dependency
Issues or PRs related to dependency changes
sig/architecture
Categorizes an issue or PR as relevant to SIG Architecture.
sig/security
Categorizes an issue or PR as relevant to SIG Security.
Description
Run
govulncheck
when a new PR is opened for go module changes to understand if the new changes are bringing newer vulnerabilities than the ones affecting main (master) branch.Implementation Details
govulncheck-presubmit.yaml
that looks something like this:Add a new file
sig-security-tooling/govulncheck/hack/govulncheck-presubmit.sh
in https://github.com/kubernetes/sig-securityTips and Caveats
|| true
is set so that the job doesn't fail since it's non-blockingParent Issue
#95
/sig security architecture
/area dependency security
The text was updated successfully, but these errors were encountered: