The Security Scanning job's govulncheck step died mid-scan on a transient network error (fetching vulnerabilities: Get https://vuln.go.dev/index/modules.json.gz: connection reset by peer) on run 29516272147, cascading into the SARIF upload steps and a red job despite 0 actual vulnerabilities (verified locally across all 6 modules at the pinned v1.1.4). Add a small bounded retry (e.g. 3 attempts, backoff) around the per-module govulncheck invocation in .github/workflows/ci.yml so a dropped connection to the live vuln DB does not fail CI. Keep the pin; a genuine vulnerability finding must still fail the job. Same pattern could guard the SARIF upload steps ('Path does not exist' cascades).
The Security Scanning job's govulncheck step died mid-scan on a transient network error (
fetching vulnerabilities: Get https://vuln.go.dev/index/modules.json.gz: connection reset by peer) on run 29516272147, cascading into the SARIF upload steps and a red job despite 0 actual vulnerabilities (verified locally across all 6 modules at the pinned v1.1.4). Add a small bounded retry (e.g. 3 attempts, backoff) around the per-module govulncheck invocation in .github/workflows/ci.yml so a dropped connection to the live vuln DB does not fail CI. Keep the pin; a genuine vulnerability finding must still fail the job. Same pattern could guard the SARIF upload steps ('Path does not exist' cascades).