Files
mfer/script/vulncheck
T
clawbot e745e18274
check / check (push) Failing after 5s
Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102)
Go 1.27.1 in go.mod and in the Dockerfile's test and build images.
Every module go.mod requires is at its current release; protoc-gen-go
follows protobuf to v1.36.12 and mf.pb.go is regenerated. The new
standard library uuid package replaces github.com/google/uuid; the
FromBytes call could only fail on a length validateUUID already checks,
so it and its unreachable error are gone. make vulncheck runs
govulncheck v1.8.0, installed with go install at its release commit, in
a vulncheck stage of the Dockerfile on the digest-pinned golang image;
script/check does not run it. A new test pins the bytes of a seeded
manifest written by an mfer built before this change.

Model: opus-5-5
2026-10-06 10:14:43 +00:00

23 lines
715 B
Bash
Executable File

#!/bin/sh
# script/vulncheck: report known vulnerabilities in the code mfer calls,
# with govulncheck, which reads the Go vulnerability database online.
# It runs as the vulncheck stage of the Dockerfile, on the same Go as the
# test phase, and this builds that stage alone, on the same terms as
# script/lint and script/test.
#
# script/check does not run it: the gate's result depends on this tree
# alone, and this one changes whenever a new advisory is published.
set -eu
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
main() {
cd "$ROOT"
docker build --no-cache \
--target vulncheck \
-t "$("$SCRIPT_DIR/projectname")-vulncheck" .
}
main "$@"