Repository navigation
chore: govulncheck no pre-push e no ci para todos os modulos - #29
Merged
Merged
Conversation
NicolasArthurDev
left a comment
Contributor
There was a problem hiding this comment.
Pequeno e correto. CI e hook usando o mesmo script é a escolha certa.
- Hook lento e dependente de rede. O
go run govulncheck@v1.8.0baixa a base de vulnerabilidades a cada execução, em todos os módulos, em todo commit que mexe em Go. Sem rede, o commit falha. Sugirostages: [pre-push]no.pre-commit-config.yaml. - Repositório sem nenhum módulo passa calado. O teste não cobre esse caso.
- O teste não confere os argumentos do
go. O go falso só registra onde rodou. Trocarrun govulncheck ./...por qualquer outra coisa continua passando. - Menor:
for gomod in $(git ls-files ...)quebra com caminho que tenha espaço.git ls-files -zcomwhile read -d ''resolve.
NicolasArthurDev
requested changes
Oct 2, 2026
NicolasArthurDev
approved these changes
Oct 2, 2026
NicolasArthurDev
left a comment
Contributor
There was a problem hiding this comment.
Valeu pelos ajustes, ficou muito bom! O hook no pre-push resolve a questão da rede sem perder a proteção, e o teste agora confere os argumentos, o caminho com espaço e o repositório sem módulo. A mensagem de erro quando não há go.mod também ficou bem clara. Aprovado.
4 tasks done
3 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
O que mudou
scripts/govulncheck-modulos.shroda o govulncheck em todo módulo Go versionado no repositório, inclusive com espaço no caminho, e reprova se não achar nenhum módulogovulncheckno pre-push, disparado quando o push leva.go,go.modougo.summake test-scripts, conferindo os argumentos passados aogoPor quê
Como testar
make hookspara instalar o gatilho de pre-pushpre-commit run govulncheck --hook-stage pre-push --all-filesmake test-scriptsAuto-review (checklist)