Skip to content

govulncheck-action: Release current master to have tagged version utilizing the full commit SHAs of transitive actions #78345

Description

@nb-99

Hi,

We are currently refactoring our actions to utilize full commit SHAs instead of tags. Using the SHA of the latest released version of golang/govulncheck-action@b625fbe08f3bccbe446d94fbf87fcc875a4f50ee #v1.0.4 fails, because v1.0.4 brings transitive actions pinned to tags, not SHAs.
Could you release a v1.0.5 from current master so that Dependabot will properly pick up future updates and we can use a tag's commit SHA instead of the current master?

Thanks and best regards,
Niklas

Metadata

Metadata

Assignees

No one assigned

    Labels

    NeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.vulncheck or vulndbIssues for the x/vuln or x/vulndb repo

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions