Skip to content

chore: govulncheck no pre-push e no ci para todos os modulos - #29

Merged
thnbi merged 9 commits into
devfrom
chore/govulncheck-no-pre-commit
Oct 3, 2026
Merged

thnbi merged 9 commits into
devfrom
chore/govulncheck-no-pre-commit

Conversation

@thnbi

@thnbi thnbi commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

O que mudou

  • Script scripts/govulncheck-modulos.sh roda o govulncheck em todo módulo Go versionado no repositório, inclusive com espaço no caminho, e reprova se não achar nenhum módulo
  • Hook govulncheck no pre-push, disparado quando o push leva .go, go.mod ou go.sum
  • CI passa a usar o mesmo script, cobrindo todos os módulos e não só o do servidor
  • Teste do script no make test-scripts, conferindo os argumentos passados ao go

Por quê

Como testar

  • make hooks para instalar o gatilho de pre-push
  • pre-commit run govulncheck --hook-stage pre-push --all-files
  • make test-scripts

Auto-review (checklist)

  • Descrição clara (o que/por quê/como testar)
  • PR pequeno e focado
  • Casos limite considerados (ex.: vazio, 0, erro)
  • Evidência de teste (manual ou automatizado)

@thnbi
thnbi requested a review from NicolasArthurDev October 1, 2026 01:05
@thnbi thnbi self-assigned this Oct 1, 2026
@thnbi thnbi added the enhancement New feature or request label Oct 1, 2026

@NicolasArthurDev NicolasArthurDev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pequeno e correto. CI e hook usando o mesmo script é a escolha certa.

  • Hook lento e dependente de rede. O go run govulncheck@v1.8.0 baixa a base de vulnerabilidades a cada execução, em todos os módulos, em todo commit que mexe em Go. Sem rede, o commit falha. Sugiro stages: [pre-push] no .pre-commit-config.yaml.
  • Repositório sem nenhum módulo passa calado. O teste não cobre esse caso.
  • O teste não confere os argumentos do go. O go falso só registra onde rodou. Trocar run govulncheck ./... por qualquer outra coisa continua passando.
  • Menor: for gomod in $(git ls-files ...) quebra com caminho que tenha espaço. git ls-files -z com while read -d '' resolve.

@NicolasArthurDev NicolasArthurDev left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Para aprovar: mover o hook do govulncheck para stages: [pre-push], para o commit não depender de rede, e cobrir no teste o repositório sem módulo e os argumentos passados ao go.

@thnbi thnbi changed the title chore: govulncheck no pre-commit e no ci para todos os modulos chore: govulncheck no pre-push e no ci para todos os modulos Oct 2, 2026
@thnbi
thnbi requested a review from NicolasArthurDev October 2, 2026 22:47

@NicolasArthurDev NicolasArthurDev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Valeu pelos ajustes, ficou muito bom! O hook no pre-push resolve a questão da rede sem perder a proteção, e o teste agora confere os argumentos, o caminho com espaço e o repositório sem módulo. A mensagem de erro quando não há go.mod também ficou bem clara. Aprovado.

@thnbi
thnbi merged commit b4e98f0 into dev Oct 3, 2026
2 checks passed
@thnbi
thnbi deleted the chore/govulncheck-no-pre-commit branch October 3, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants