Skip to content

[Security Scan] 2026-W28 #80

Description

@github-actions

Weekly Supply Chain Security Scan

Risk Summary

  • Risk level: HIGH
  • Risk score: 51
  • govulncheck exit code: 0 (3 = call-graph-reachable vulnerability)
  • Stale dependencies (>90 days): false

Top Findings

See the workflow run for full SARIF (gosec) and JSON (govulncheck, unisupply) output.
The gosec findings are also visible under Security → Code scanning.

Stale Dependencies

Direct dependencies with available updates

(none)

Dependencies older than 90 days

(none)

Closure guidance

Close this issue only after the underlying findings are actioned (e.g.
dependency bumps merged, vulnerabilities resolved, annotations added). Closing
the issue does not silence future scans — a fresh issue is filed each ISO week.

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-scanWeekly supply chain security scan findings

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions