Skip to content

ci: govulncheck step should retry transient vuln-DB fetch failures #74

Description

@cristim

The Security Scanning job's govulncheck step died mid-scan on a transient network error (fetching vulnerabilities: Get https://vuln.go.dev/index/modules.json.gz: connection reset by peer) on run 29516272147, cascading into the SARIF upload steps and a red job despite 0 actual vulnerabilities (verified locally across all 6 modules at the pinned v1.1.4). Add a small bounded retry (e.g. 3 attempts, backoff) around the per-module govulncheck invocation in .github/workflows/ci.yml so a dropped connection to the live vuln DB does not fail CI. Keep the pin; a genuine vulnerability finding must still fail the job. Same pattern could guard the SARIF upload steps ('Path does not exist' cascades).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions