Skip to content

Bump golang.org/x/term from 0.39.0 to 0.43.0 (#23) #113

Bump golang.org/x/term from 0.39.0 to 0.43.0 (#23)

Bump golang.org/x/term from 0.39.0 to 0.43.0 (#23) #113

Workflow file for this run

name: gopresubmit
on:
push:
branches:
- main
pull_request:
types: [opened, reopened, synchronize]
permissions:
contents: read
jobs:
build:
name: Go presubmit
runs-on: ubuntu-latest
strategy:
matrix:
go-version: ['1.22']
steps:
- name: Install Go ${{ matrix.go-version }}
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
with:
go-version: ${{ matrix.go-version }}
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Security scan for dangerous Go patterns
run: |
# Detect go:generate directives (potential code execution)
if grep -rn '//go:generate' --include='*.go' .; then
echo "::error::Detected //go:generate directive - requires manual review"
exit 1
fi
# Detect CGo usage (native code execution during build)
if grep -rn 'import "C"' --include='*.go' .; then
echo "::error::Detected CGo import - requires manual review"
exit 1
fi
# Detect #cgo directives
if grep -rn '#cgo' --include='*.go' .; then
echo "::error::Detected #cgo directive - requires manual review"
exit 1
fi
- uses: creachadair/go-presubmit-action@4f7a734aa8275675a945fbf589734f8cf7dda58a # v2.0.3
with:
staticcheck-version: "2023.1.6"