defenseunicorns/lula

Integrate govulncheck into pipeline workflows

Opened this issue · 0 comments

Is your feature request related to a problem? Please describe.

After recent golang vulnerabilities reported - it would be of interest to add govulncheck to the project workflows as an additional language-specific vulnerability scanner that could provide value for the ability to respond and mitigate or remediate in a timely manner.

Additional context

Will file another issue for the nightly running of scanning and tests of the project