#!/bin/sh # script/vulncheck: report known vulnerabilities in the code mfer calls, # with govulncheck, which reads the Go vulnerability database online. # It runs as the vulncheck stage of the Dockerfile, on the same Go as the # test phase, and this builds that stage alone, on the same terms as # script/lint and script/test. # # script/check does not run it: the gate's result depends on this tree # alone, and this one changes whenever a new advisory is published. set -eu SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)" ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)" main() { cd "$ROOT" docker build --no-cache \ --target vulncheck \ -t "$("$SCRIPT_DIR/projectname")-vulncheck" . } main "$@"