Problem
Three sources currently pin gosec to inconsistent versions:
PR #1245 deliberately aligned the Makefile with pre-commit.yml so install-dev-tools matches what pre-commit runs locally and in CI. The bigger problem is that pre-commit.yml's own pin (and its anchor comment, "Pinned to the same version ci.yml's securego/gosec Action uses") have been stale since PR #536 bumped ci.yml's Docker Action to v2.26.1.
Result: developers running the gosec scan locally via make install-dev-tools + make security-scan-go see a different gosec rule-set than the SARIF scan ci.yml uploads to GitHub Security. A new HIGH/CRITICAL rule shipped in v2.23.0+ would fail in CI while passing locally, or vice versa.
Proposed fix
Either:
- Track ci.yml (preferred) — bump
pre-commit.yml and the Makefile GOSEC_VERSION to v2.26.1 (or the next ci.yml bump), refresh the pre-commit.yml comment.
- Track pre-commit.yml — pin ci.yml's Docker Action down to v2.22.x.
Whichever direction, fix all three sources in one PR so the Makefile comment ("keep in sync with the CI pins in .github/workflows/ci.yml, pre-commit.yml and database-migration.yml") becomes true.
References
Scope after the split
This repo (cloud-commitments-cli) is one of four repos affected, each with its own ci.yml, pre-commit.yml, Makefile and scripts/gosec-hook.sh; this issue now scopes to only this repo's own files. Siblings for the other three:
Re-verified live on 2026-09-27, this repo's own state has moved on from what's described above (a comment on this issue from a maintainer, dated after the original filing, re-checked commit 3e9660d06): the original three-way version drift (v2.26.1 vs v2.22.4) is already fixed — ci.yml:328 no longer uses the securego/gosec Docker Action at all; all four current pin sites (ci.yml:328, pre-commit.yml:60/:67, Makefile:7, and a fourth site not in the original issue, scripts/gosec-hook.sh:35) now agree on v2.28.0. What's still open in this repo: the pre-commit.yml comment still wrongly claims to track a securego/gosec Action that no longer exists in ci.yml; the Makefile comment's claim to sync with database-migration.yml is still false (that workflow pins no gosec version); and the gosec install step + cache key in pre-commit.yml are dead code, since the gosec pre-commit hook is SKIPped in CI. Fix direction: single-source the version across all four sites and delete the dead pre-commit install step. This overlaps #1394 (pre-commit vs CI gosec rule-set divergence, a related but distinct problem); landing both as one "single source of truth for gosec" change avoids touching the same lines twice.
Problem
Three sources currently pin
gosecto inconsistent versions:.github/workflows/ci.yml:321—securego/gosec@4a3bd8af174872c778439083ded7adbf3747e770 # v2.26.1(Docker Action, bumped in PR sec(ci): pin all GitHub Actions to commit SHAs #536).github/workflows/pre-commit.yml:97—go install ...@v2.22.4(with stale comment claiming it tracks ci.yml)Makefileinstall-dev-tools—GOSEC_VERSION?=v2.22.4(added by PR chore(make): drop broken recipes, pin dev tools, add ci to .PHONY #1245, aligned with pre-commit.yml)PR #1245 deliberately aligned the Makefile with
pre-commit.ymlsoinstall-dev-toolsmatches what pre-commit runs locally and in CI. The bigger problem is thatpre-commit.yml's own pin (and its anchor comment, "Pinned to the same version ci.yml'ssecurego/gosecAction uses") have been stale since PR #536 bumped ci.yml's Docker Action to v2.26.1.Result: developers running the gosec scan locally via
make install-dev-tools+make security-scan-gosee a different gosec rule-set than the SARIF scan ci.yml uploads to GitHub Security. A new HIGH/CRITICAL rule shipped in v2.23.0+ would fail in CI while passing locally, or vice versa.Proposed fix
Either:
pre-commit.ymland the MakefileGOSEC_VERSIONtov2.26.1(or the next ci.yml bump), refresh the pre-commit.yml comment.Whichever direction, fix all three sources in one PR so the Makefile comment ("keep in sync with the CI pins in
.github/workflows/ci.yml,pre-commit.ymlanddatabase-migration.yml") becomes true.References
sec(ci): pin all GitHub Actions to commit SHAs) bumped ci.yml's gosec Action to v2.26.1 without touching pre-commit.yml.fix(ci): pin actions to latest SHA of the in-use major, not a downgraded major) is the actual commit that landed the v2.26.1 bump.Scope after the split
This repo (
cloud-commitments-cli) is one of four repos affected, each with its ownci.yml,pre-commit.yml,Makefileandscripts/gosec-hook.sh; this issue now scopes to only this repo's own files. Siblings for the other three:Re-verified live on 2026-09-27, this repo's own state has moved on from what's described above (a comment on this issue from a maintainer, dated after the original filing, re-checked commit
3e9660d06): the original three-way version drift (v2.26.1 vs v2.22.4) is already fixed —ci.yml:328no longer uses thesecurego/gosecDocker Action at all; all four current pin sites (ci.yml:328,pre-commit.yml:60/:67,Makefile:7, and a fourth site not in the original issue,scripts/gosec-hook.sh:35) now agree on v2.28.0. What's still open in this repo: thepre-commit.ymlcomment still wrongly claims to track asecurego/gosecAction that no longer exists inci.yml; theMakefilecomment's claim to sync withdatabase-migration.ymlis still false (that workflow pins no gosec version); and the gosec install step + cache key inpre-commit.ymlare dead code, since thegosecpre-commit hook isSKIPped in CI. Fix direction: single-source the version across all four sites and delete the dead pre-commit install step. This overlaps #1394 (pre-commit vs CI gosec rule-set divergence, a related but distinct problem); landing both as one "single source of truth for gosec" change avoids touching the same lines twice.