With govulncheck (#1343) and npm audit (#1345) now green, the Security Scanning job's remaining failure is the gosec static-analysis step. Likely pre-existing gosec debt newly surfaced (earlier steps used to fail first). Run gosec ./... per the CI job config, triage each finding (real vuln vs false positive), fix real ones, and justify suppressions individually with #nosec + reason (no blanket excludes). Part of the main-CI-green effort alongside #1342 (Lint).
With govulncheck (#1343) and npm audit (#1345) now green, the Security Scanning job's remaining failure is the gosec static-analysis step. Likely pre-existing gosec debt newly surfaced (earlier steps used to fail first). Run
gosec ./...per the CI job config, triage each finding (real vuln vs false positive), fix real ones, and justify suppressions individually with #nosec + reason (no blanket excludes). Part of the main-CI-green effort alongside #1342 (Lint).