Skip to content

Releases: Templum/govulncheck-action

v1.0.1

02 Nov 11:57
0d775f4
Compare
Choose a tag to compare

⚠️ This release increases the default version of govulncheck, which requires golang >= 1.21. Hence only update if your project is leveraging golang version 1.21.

What's Changed

  • Maintain major/minor tags by @anton-yurchenko in #49
  • ⬆️ Bump github.com/rs/zerolog from 1.29.1 to 1.30.0 by @dependabot in #50
  • 👷 ✨ Integration Test that can run on (forked) PR by @Templum in #52
  • ⬆️ Bump golang.org/x/oauth2 from 0.10.0 to 0.11.0 by @dependabot in #51
  • ⬆️ Bump actions/checkout from 3 to 4 by @dependabot in #54
  • ⬆️ Bump golang.org/x/oauth2 from 0.11.0 to 0.12.0 by @dependabot in #55
  • ⬆️ Bump codecov/codecov-action from 3 to 4 by @dependabot in #56
  • 🐛 Fixed issue with code cov by @Templum in #59
  • ⬆️ Bump github.com/rs/zerolog from 1.30.0 to 1.31.0 by @dependabot in #58
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.2.0 to 2.2.2 by @dependabot in #57
  • ⬆️ Bump golang.org/x/net from 0.15.0 to 0.17.0 by @dependabot in #62
  • ⬆️ Bump golang.org/x/oauth2 from 0.12.0 to 0.13.0 by @dependabot in #61
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.2.2 to 2.3.0 by @dependabot in #60
  • ⬆️ Bump golang.org/x/oauth2 from 0.13.0 to 0.14.0 by @dependabot in #63
  • ⬆️ Bump golang from 1.20 to 1.21 by @dependabot in #53
  • ⬆️ Bump golang.org/x/oauth2 from 0.14.0 to 0.15.0 by @dependabot in #64
  • ⬆️ Bump actions/setup-go from 4 to 5 by @dependabot in #65
  • ⬆️ Bump actions/upload-artifact from 3 to 4 by @dependabot in #66
  • ⬆️ Bump golang.org/x/crypto from 0.16.0 to 0.17.0 by @dependabot in #67
  • ⬆️ Bump golang.org/x/oauth2 from 0.15.0 to 0.16.0 by @dependabot in #68
  • ⬆️ Bump github.com/rs/zerolog from 1.31.0 to 1.32.0 by @dependabot in #70
  • ⬆️ Bump golang.org/x/oauth2 from 0.16.0 to 0.17.0 by @dependabot in #71
  • ⬆️ Bump golang from 1.21 to 1.22 by @dependabot in #72
  • ⬆️ Bump codecov/codecov-action from 3 to 4 by @dependabot in #69
  • ⬆️ Bump github.com/stretchr/testify from 1.8.4 to 1.9.0 by @dependabot in #73
  • ⬆️ Bump golang.org/x/oauth2 from 0.17.0 to 0.18.0 by @dependabot in #74
  • ⬆️ Bump softprops/action-gh-release from 1 to 2 by @dependabot in #75
  • ⬆️ Bump google.golang.org/protobuf from 1.31.0 to 1.33.0 by @dependabot in #76
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.3.0 to 2.3.1 by @dependabot in #77
  • ⬆️ Bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 by @dependabot in #78
  • ✨ Better & Improved error propagation from govulncheck thrown errors. by @Templum in #81
  • ⬆️ Bump golang.org/x/oauth2 from 0.19.0 to 0.20.0 by @dependabot in #82
  • ⬆️ Bump github.com/rs/zerolog from 1.32.0 to 1.33.0 by @dependabot in #83
  • ⬆️ Bump golang.org/x/oauth2 from 0.20.0 to 0.21.0 by @dependabot in #84
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.3.1 to 2.3.2 by @dependabot in #85
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.3.2 to 2.3.3 by @dependabot in #86
  • ⬆️ Bump golang.org/x/oauth2 from 0.21.0 to 0.22.0 by @dependabot in #87
  • ⬆️ Bump golang from 1.22 to 1.23 by @dependabot in #88
  • ⬆️ Bump golang.org/x/oauth2 from 0.22.0 to 0.23.0 by @dependabot in #89
  • 📌 Set Default version to latest by @Templum in #92
  • 🐛 Fixing Bug with latest version causing integration test to fail by @Templum in #93

New Contributors

Full Changelog: v1.0.0...v1.0.1

v1.0.0

21 Jul 17:27
6bb063b
Compare
Choose a tag to compare

What's Changed

💥⚠️ This release contains breaking changes that are not backwards compatible with v0 version of govulncheck. So if you upgrade make sure to select 1.0 (or above). The defaults of the action also have been updated to reflect this.

  • 💥 👽 Adjusted code to vulncheck 1.0 (breaks with v0 code) by @Templum in #48

Full Changelog: v0.11.0...v1.0.0

v0.10.1

25 Apr 15:51
435a35e
Compare
Choose a tag to compare

What's Changed

  • ⬆️ Bump golang.org/x/oauth2 from 0.6.0 to 0.7.0 by @dependabot in #35
  • 👽 Added support for the new JSON Format by @Templum in #34
  • ⬆️ Bump github.com/rs/zerolog from 1.29.0 to 1.29.1 by @dependabot in #36
  • ⬆️ 📌 Update & Pinned govulncheck to 0.1.0 by @Templum in #38

Full Changelog: v0.10.0...v0.10.1

v0.10.0

21 Mar 22:42
af8ff86
Compare
Choose a tag to compare

🚨 Please be aware that yesterdays release of govulncheck introduced a change to the json report format. This caused the action to break, as govulncheck is still in v0 phase such changes can be expected. In order to address them properly I decided to set the default govulncheck version to the last known working version (at release time this is 0.0.0-20230320232729-bfc1eaef17a4). 🚨

Please avoid setting vulncheck-version: latest as this could break on new releases.

What's Changed

  • ⬆️ Bump github.com/rs/zerolog from 1.28.0 to 1.29.0 by @dependabot in #23
  • ⬆️ Updated Golang to 1.20.0 by @Templum in #25
  • ⬆️ Bump golang.org/x/oauth2 from 0.0.0-20220909003341-f21342109be1 to 0.5.0 by @dependabot in #26
  • ⬆️ Bump github.com/stretchr/testify from 1.8.1 to 1.8.2 by @dependabot in #27
  • ⬆️ Bump golang.org/x/oauth2 from 0.5.0 to 0.6.0 by @dependabot in #28
  • ⬆️ Bump actions/setup-go from 3 to 4 by @dependabot in #29
  • ⬆️ Bump github.com/owenrumney/go-sarif/v2 from 2.1.2 to 2.1.3 by @dependabot in #30
  • 🐛 👽 Updated action to work with latest json format by @Templum in #32

Full Changelog: v0.0.9...v0.10.0

v0.0.9

11 Jan 20:57
dfb34f5
Compare
Choose a tag to compare

What's Changed

  • 📝 Added New Configuration Examples by @Templum in #18
  • ✨ Implement support for private deps via GOPRIVATE & GH PAT by @Templum in #21
  • 👷 Implement Integration Test by @Templum in #22

Full Changelog: v0.0.8...v0.0.9

v0.0.8

17 Nov 14:29
f115ae3
Compare
Choose a tag to compare

What's Changed

  • ✨ 🐛 Reading Go Runtime Details from GOENV by @Templum in #17

Full Changelog: v0.0.7...v0.0.8

v0.0.7

16 Nov 16:02
d00d03e
Compare
Choose a tag to compare

What's Changed

🚨 Please be aware this Release includes a fix in response to an internal change in the govulncheck CLI, the JSON Report format was drastically changed which broke this action. 🚨

  • 👽 ✨ Adjusted Action to work with new Report Format by @Templum in #15

Full Changelog: v0.0.6...v0.0.7

v0.0.6

06 Nov 22:16
c75372f
Compare
Choose a tag to compare

What's Changed

  • 👷 ✅ Added CI Pipeline & Unit Tests by @Templum in #5
  • 📝 Adding/Fixing Links for Badge by @Templum in #6
  • ⬆️ Bump github.com/google/go-github/v47 from 47.0.0 to 47.1.0 by @dependabot in #7
  • 🐛 Decoupled Debug Level Logs by @Templum in #8
  • ⬆️ Bump github.com/stretchr/testify from 1.8.0 to 1.8.1 by @dependabot in #9
  • ✨ Implemented Strict Mode Support by @Templum in #12
  • ✨ Allow skipping Sarif Upload by @Templum in #13

New Contributors

Full Changelog: v0.0.5...v0.0.6

v0.0.5

17 Sep 21:37
db747f2
Compare
Choose a tag to compare

What's Changed

  • 🐛 ✨ Implemented proper Resolution of Callsites by @Templum in #4

Full Changelog: v0.0.4...v0.0.5

v0.0.4

15 Sep 14:13
Compare
Choose a tag to compare

What's Changed

  • ✨ Allowing better configuration for the action by @Templum in #3

Full Changelog: v0.0.3...v0.0.4