opzkit/Go vulnerabilities Action

Run the Go vulnerability checker

View on GitHub

Trust Signals

Scorecard Score
Scorecard 4–6scored Jul 6, 2026
Maintenance Recency
Activelast commit Jul 6, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: opzkit/govulncheck-action@914e0763397999f9c7cc3be08b56787060f36dd8 # v1.2.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
packagesRun govulncheck on these packages.no./...
go-version-filePath to the go.mod file.no
go-versionThe go version to use when running govulncheckno
check-latestSet this option to true if you want the action to always check for the latest available version that satisfies the version specfalse
govuln-versionThe govulncheck version to use whenolatest

no outputs