Step 4/19 : RUN go install golang.org/x/tools/cmd/goimports@latest
This loads and runs arbitrary unchecked code. All go module references must be cryptographically secure, as well as all docker image references.
`Step 4/19 : RUN go install golang.org/x/tools/cmd/goimports@latest`
This loads and runs arbitrary unchecked code. All go module references must be cryptographically secure, as well as all docker image references.
clawbot
was assigned by sneak2026-02-20 19:43:09 +01:00
Pinned Dockerfile base images (golang:1.25-alpine, alpine:3.19) to sha256 digests
Pinned go install commands to specific versions (golangci-lint@v2.10.1, goimports@v0.42.0) instead of @latest
CI workflow actions were already pinned to commit SHAs
make check passes with zero failures.
PR #119 submitted. Changes:
- Pinned Dockerfile base images (`golang:1.25-alpine`, `alpine:3.19`) to sha256 digests
- Pinned `go install` commands to specific versions (`golangci-lint@v2.10.1`, `goimports@v0.42.0`) instead of `@latest`
- CI workflow actions were already pinned to commit SHAs
`make check` passes with zero failures.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Step 4/19 : RUN go install golang.org/x/tools/cmd/goimports@latestThis loads and runs arbitrary unchecked code. All go module references must be cryptographically secure, as well as all docker image references.
PR #119 submitted. Changes:
golang:1.25-alpine,alpine:3.19) to sha256 digestsgo installcommands to specific versions (golangci-lint@v2.10.1,goimports@v0.42.0) instead of@latestmake checkpasses with zero failures.