Documentation
¶
Overview ¶
Command govulncheck-to-gitlab converts `govulncheck -format json` output into a GitLab Dependency Scanning report.
Only symbol-reachable findings are reported. govulncheck emits each vulnerability three times, at module, package and symbol level; the first two mean "this version is in our module graph", which is what the SBOM analyzer already tells us. A symbol-level finding means our code has a call path into the vulnerable function, which is the thing worth acting on.
The exit code is 3 when a reachable finding is not on the ignore list, so a caller can gate on it, and 1 when the input could not be processed at all. Reporting nothing because govulncheck crashed must not look like success.