Skip to content

ci: scan security on maintained Go and preserve minimum compatibility - #4

Merged
strider2038 merged 2 commits into
mainfrom
ci/separate-security-diagnostics
Oct 5, 2026
Merged

strider2038 merged 2 commits into
mainfrom
ci/separate-security-diagnostics

Conversation

@strider2038

@strider2038 strider2038 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Share required verification between PR CI and maintainer-dispatched releases: existing quality gates, minimum-Go build/tests, and Security using govulncheck v1.8.0 with Go 1.26.6. Security fails on findings and scanner/setup errors and retains summaries and scanner output artifacts. There is no legacy security job in CI or releases; old-toolchain security audits can be performed manually when needed.

Release documentation explains the compatibility/security policy and identifies quality/minimum/Security as the required checks to configure in branch protection. Hosted rules currently have no required checks configured.

Validation

  • actionlint, shell syntax and git diff --check passed.
  • Scanner fixtures verify clean results, findings, operational errors, missing scanner and failed toolchain preflight; every nonzero scanner result fails.
  • Prior CI passed all library checks (Squirrel fuzz timed out once and passed on retry). CI reruns on this update.
  • No release or tag was created.

@strider2038 strider2038 changed the title ci: separate required security from legacy Go diagnostics ci: scan security on maintained Go and preserve minimum compatibility Oct 2, 2026
@strider2038
strider2038 merged commit 740683b into main Oct 5, 2026
3 checks passed
@strider2038
strider2038 deleted the ci/separate-security-diagnostics branch October 5, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant