Add govulncheck to default go-workflow

Scan Go dependencies against the vulnerability database automatically
on every run, between vet and test. Fail fast on known CVEs before
spending time running the full test suite.
- rootfs/usr/local/bin/go-workflow: add govulncheck ./... as step 4; renumber build to step 6
- README.md: update default workflow diagram to include govulncheck

README.md
rootfs/usr/local/bin/go-workflow
This commit is contained in:
casjay
2026-07-03 11:14:46 -04:00
parent 3ba7473c95
commit bc1eb17c2f
2 changed files with 5 additions and 3 deletions
+1 -1
View File
@@ -25,7 +25,7 @@ Mount your project at `/app` and run with no arguments. The container
automatically runs the full Go workflow:
```
go mod tidy → gofmt -w . → go vet ./... → go test ./... → go build ./...
go mod tidy → gofmt -w . → go vet ./... → govulncheck ./... → go test ./... → go build ./...
```
```shell
+4 -2
View File
@@ -61,9 +61,11 @@ run_step "go mod tidy" go mod tidy
run_step "gofmt -w ." gofmt -w .
# 3. Catch suspicious constructs
run_step "go vet ./..." go vet ./...
# 4. Run tests — fail fast before wasting time on a build
# 4. Scan dependencies against the Go vulnerability database
run_step "govulncheck ./..." govulncheck ./...
# 5. Run tests — fail fast before wasting time on a build
run_step "go test ./..." go test ./...
# 5. Build all main packages; output lands alongside source in each package dir
# 6. Build all main packages; output lands alongside source in each package dir
run_step "go build ./..." go build "${BUILD_FLAGS[@]}" ./...
echo "✅ Done."