globocom / huskyCI

Performing security tests inside your CI
https://huskyci.opensource.globo.com
BSD 3-Clause "New" or "Revised" License
572 stars 137 forks source link

Add Govulncheck as a new securityTest #546

Open fguisso opened 2 years ago

fguisso commented 2 years ago

image

Motivation

Golang Security team has developed a new tool to detect vulnerable packages in Golang code and it will be a great addition to huskyCI analysis.

It would be great if

We have all the necessary code to run this scan!

What we expect

Tips

vitorduarte commented 2 years ago

config.yaml file doesn't seem to be available

fguisso commented 1 year ago

We are testing a more complete solution for SCA, probably we will drop this issue beside the implement anti on of osvscanner + cdxgen