Skip to content

ci: align gosec pin across ci.yml, pre-commit.yml, and Makefile #1297

Description

@cristim

Problem

Three sources currently pin gosec to inconsistent versions:

PR #1245 deliberately aligned the Makefile with pre-commit.yml so install-dev-tools matches what pre-commit runs locally and in CI. The bigger problem is that pre-commit.yml's own pin (and its anchor comment, "Pinned to the same version ci.yml's securego/gosec Action uses") have been stale since PR #536 bumped ci.yml's Docker Action to v2.26.1.

Result: developers running the gosec scan locally via make install-dev-tools + make security-scan-go see a different gosec rule-set than the SARIF scan ci.yml uploads to GitHub Security. A new HIGH/CRITICAL rule shipped in v2.23.0+ would fail in CI while passing locally, or vice versa.

Proposed fix

Either:

  1. Track ci.yml (preferred) — bump pre-commit.yml and the Makefile GOSEC_VERSION to v2.26.1 (or the next ci.yml bump), refresh the pre-commit.yml comment.
  2. Track pre-commit.yml — pin ci.yml's Docker Action down to v2.22.x.

Whichever direction, fix all three sources in one PR so the Makefile comment ("keep in sync with the CI pins in .github/workflows/ci.yml, pre-commit.yml and database-migration.yml") becomes true.

References

Scope after the split

This repo (cloud-commitments-cli) is one of four repos affected, each with its own ci.yml, pre-commit.yml, Makefile and scripts/gosec-hook.sh; this issue now scopes to only this repo's own files. Siblings for the other three:

Re-verified live on 2026-09-27, this repo's own state has moved on from what's described above (a comment on this issue from a maintainer, dated after the original filing, re-checked commit 3e9660d06): the original three-way version drift (v2.26.1 vs v2.22.4) is already fixed — ci.yml:328 no longer uses the securego/gosec Docker Action at all; all four current pin sites (ci.yml:328, pre-commit.yml:60/:67, Makefile:7, and a fourth site not in the original issue, scripts/gosec-hook.sh:35) now agree on v2.28.0. What's still open in this repo: the pre-commit.yml comment still wrongly claims to track a securego/gosec Action that no longer exists in ci.yml; the Makefile comment's claim to sync with database-migration.yml is still false (that workflow pins no gosec version); and the gosec install step + cache key in pre-commit.yml are dead code, since the gosec pre-commit hook is SKIPped in CI. Fix direction: single-source the version across all four sites and delete the dead pre-commit install step. This overlaps #1394 (pre-commit vs CI gosec rule-set divergence, a related but distinct problem); landing both as one "single source of truth for gosec" change avoids touching the same lines twice.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions