Skip to content

chore: Pin OSV Go dependencies to stable pseudo-version#294

Open
jess-lowe wants to merge 1 commit into
pypa:mainfrom
jess-lowe:chore/pin-osv-deps
Open

chore: Pin OSV Go dependencies to stable pseudo-version#294
jess-lowe wants to merge 1 commit into
pypa:mainfrom
jess-lowe:chore/pin-osv-deps

Conversation

@jess-lowe

Copy link
Copy Markdown
Contributor

Due to this project's workflow fetching the osv vulnfeeds master branch directly, the GitHub actions relying on the OSV code broke the CI for a while.

Now that that is all fixed, in order to prevent this from happening again, I've updated the workflow to stop tracking master.

This PR points directly to the newly isolated /external directory and pins it to a specific, stable Go pseudo-version.

@di

di commented May 26, 2026

Copy link
Copy Markdown
Member

I'm assuming dependabot will not catch these as new versions are released. Is there another way for this repo to be notified when there are new versions to use? Or could we make it part of the release flow to update the pin here?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants