govulncheck-to-gitlab

command
v1.120.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Overview

Command govulncheck-to-gitlab converts `govulncheck -format json` output into a GitLab Dependency Scanning report.

Only symbol-reachable findings are reported. govulncheck emits each vulnerability three times, at module, package and symbol level; the first two mean "this version is in our module graph", which is what the SBOM analyzer already tells us. A symbol-level finding means our code has a call path into the vulnerable function, which is the thing worth acting on.

The exit code is 3 when a reachable finding is not on the ignore list, so a caller can gate on it, and 1 when the input could not be processed at all. Reporting nothing because govulncheck crashed must not look like success.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL