Skip to content

Commit 7699a8e

Browse files
somanshreddyclaude
andauthored
ci: allowlist govulncheck GO-2026-5932 (unmaintained x/crypto/openpgp) (#233)
govulncheck fails repo-wide on GO-2026-5932: golang.org/x/crypto/openpgp is unmaintained/unsafe by design ("Fixed in: N/A"), pulled in transitively by go-selfupdate for a PGP validator the CLI does not use — the updater verifies SHA256 checksums (ChecksumValidator), not PGP, so openpgp is never reached with untrusted input; only its package init is. Wrap the govulncheck step to pass only when GO-2026-5932 is the sole advisory (and govulncheck exited 3, vulns-found); any other advisory, or a tool/build failure, still fails the job. Removing the dependency is tracked in API-566. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 9a3a48a commit 7699a8e

1 file changed

Lines changed: 24 additions & 1 deletion

File tree

‎.github/workflows/ci.yml‎

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,30 @@ jobs:
8686
run: go install golang.org/x/vuln/cmd/govulncheck@v1.1.4
8787

8888
- name: Run govulncheck
89-
run: govulncheck ./...
89+
# Allowlist GO-2026-5932 ONLY: golang.org/x/crypto/openpgp is unmaintained
90+
# ("Fixed in: N/A") and pulled in transitively by go-selfupdate for a PGP
91+
# validator the CLI does not use — the updater verifies SHA256 checksums
92+
# (ChecksumValidator), not PGP, so openpgp is never reached with untrusted
93+
# input. Any OTHER advisory still fails this job. Removal tracked in API-566.
94+
run: |
95+
out=$(govulncheck ./... 2>&1) && rc=0 || rc=$?
96+
echo "$out"
97+
if [ "$rc" -eq 0 ]; then
98+
exit 0
99+
fi
100+
# govulncheck exits 3 when vulnerabilities are found; any other non-zero
101+
# code is a tool/build failure and must not be swallowed by the allowlist.
102+
if [ "$rc" -ne 3 ]; then
103+
echo "::error::govulncheck failed to run (exit $rc)"
104+
exit 1
105+
fi
106+
ids=$(printf '%s\n' "$out" | grep -oE 'GO-[0-9]{4}-[0-9]+' | sort -u)
107+
others=$(printf '%s\n' "$ids" | grep -vx 'GO-2026-5932' || true)
108+
if [ -z "$ids" ] || [ -n "$others" ]; then
109+
echo "::error::Unallowlisted or unrecognized govulncheck result (ids: ${ids:-none})"
110+
exit 1
111+
fi
112+
echo "Only the allowlisted advisory GO-2026-5932 is present; passing."
90113
91114
goreleaser-check:
92115
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)