Skip to content

deps: consolidated bumps (#310 #311 #314 #317) + govulncheck non-Go-PR gate#323

Merged
Cre-eD merged 5 commits into
mainfrom
deps/consolidated-2026-06-13
Jun 13, 2026
Merged

deps: consolidated bumps (#310 #311 #314 #317) + govulncheck non-Go-PR gate#323
Cre-eD merged 5 commits into
mainfrom
deps/consolidated-2026-06-13

Conversation

@Cre-eD

@Cre-eD Cre-eD commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Consolidated dependency bumps + govulncheck gate fix

Bundles the four open Dependabot PRs into one branch so they can be reviewed and merged together, plus the CI change that stops this class of false block from recurring. Each is a separate, signed commit off current main:

Commit Replaces Change
Go modules #317 17 modules in the gomod-minor-and-patch group — golang.org/x/crypto 0.52→0.53, golang.org/x/text 0.37→0.38, aws-sdk-go-v2 1.41.7→1.42.0, pulumi 3.243→3.245, gocloud.dev 0.45→0.46, google.golang.org/api 0.280→0.284, Azure SDK keyvault module restructure, + transitives
CI actions #311 actions/checkout v6.0.2→v6.0.3, github/codeql-action v4 digest
caddy #314 caddy 2.11.3→2.11.4 (builder + runtime stages)
lambda base #310 public.ecr.aws/lambda/provided:al2023 digest refresh
govulncheck gate skip the reachability scan on PRs that touch no Go input (see below)

go.mod/go.sum are byte-identical to #317's head (which already passed govulncheck + CodeQL). Locally verified: go mod tidy is a no-op and go build ./... is clean on go 1.26.4. CI on the first four commits was fully green (govulncheck, Build Setup, all Build matrix targets, Run tests, CodeQL, Fuzz).

Why the Dependabot PRs were stuck on govulncheck

govulncheck.yml uses go-version-file: go.mod, so it scans the standard library of whatever go directive the PR carries. main is now go 1.26.4 (stdlib crypto/x509 + net/textproto advisories fixed). The two June-3 PRs (#310, #311) were branched while main was still go 1.26.3, so their stale base still trips those stdlib vulns — even though one only bumps a Docker digest and the other only bumps GitHub Actions, neither of which touches Go. The June-8/11 PRs (#314, #317) were branched after the bump and pass cleanly.

The gate fix (prevents recurrence)

The 5th commit adds a "Decide whether to scan" step: on a PR it lists the changed files and runs govulncheck only when a Go input (*.go / go.mod / go.sum) changed. A PR that changes no Go input cannot alter reachability, and cannot change the stdlib version govulncheck reads from the go directive — so a Docker/Actions-only PR is skipped (and reports success) instead of re-flagging whatever sits on its stale base. The job always runs and reports, so a required status check is never left pending; main-push and the weekly cron still scan unconditionally, so nothing escapes the gate before release. This PR itself touches go.mod/go.sum, so it runs the full scan.

Once merged, the four Dependabot PRs (#310, #311, #314, #317) can be closed.

Cre-eD added 4 commits June 13, 2026 14:14
Consolidates Dependabot #310 (402646e -> 777e461).

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
Consolidates Dependabot #314 (docker-minor-and-patch group).

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
…igest

Consolidates Dependabot #311 (actions-minor-and-patch group).

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
Consolidates Dependabot #317. Includes golang.org/x/crypto 0.52->0.53,
golang.org/x/text 0.37->0.38, aws-sdk-go-v2 1.41.7->1.42.0, pulumi
3.243->3.245, gocloud.dev 0.45->0.46, google.golang.org/api 0.280->0.284,
plus Azure SDK keyvault module restructure and transitive bumps.

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
@github-actions

github-actions Bot commented Jun 13, 2026

Copy link
Copy Markdown

Semgrep Scan Results

Repository: api | Commit: 3dea9fb

Check Status Details
✅ Semgrep Pass 0 total findings (no error/warning)

Scanned at 2026-06-13 11:14 UTC

@github-actions

github-actions Bot commented Jun 13, 2026

Copy link
Copy Markdown

Security Scan Results

Repository: api | Commit: 3dea9fb

Check Status Details
✅ Secret Scan Pass No secrets detected
✅ Dependencies (Trivy) Pass 0 total (no critical/high)
✅ Dependencies (Grype) Pass 0 total (no critical/high)
📦 SBOM Generated 522 components (CycloneDX)

Scanned at 2026-06-13 11:15 UTC

govulncheck reads the stdlib version from go.mod's `go` directive via
go-version-file, so a PR branched off a stale base re-flags stdlib
advisories that main already fixed by bumping the directive — even when
the PR only touches a Dockerfile or an Actions pin. That is why the
June-3 digest/action Dependabot PRs (#310, #311) 'failed' a go 1.26.3
stdlib advisory that 1.26.4 main had already resolved.

Add a gate step that lists the PR's files and runs the scan only when a
Go input (*.go / go.mod / go.sum) changed. The job always runs and
reports, so a required status check is never left pending; main-push +
the weekly cron still scan unconditionally.

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
@Cre-eD Cre-eD changed the title deps: consolidated dependency bumps (#310 #311 #314 #317) deps: consolidated bumps (#310 #311 #314 #317) + govulncheck non-Go-PR gate Jun 13, 2026
@smecsia smecsia added the ci-run label Jun 13, 2026
@Cre-eD
Cre-eD merged commit 2deddae into main Jun 13, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants