govulncheck-apply

command module
v0.3.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 28, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

README

govulncheck-apply

Reads a govulncheck -json stream on stdin and applies the reported fixes to the go.mod(s) in the working directory: upgrades vulnerable modules and bumps the go directive for standard-library vulns. If the main module has a vendor directory, it is re-synced with go mod vendor.

Usage

go install github.com/netflix-skunkworks/govulncheck-apply@latest
govulncheck -json ./... | govulncheck-apply

Test case format

Each internal/testcases/foo.txtar is a repository to scan, plus a want_diff.txt holding the git diff the run is expected to produce. Its sibling foo.db.txtar is the vulnerability database to scan against.

In the archive comment, # lines describe the case and mean nothing to the harness. Every other non-blank line is a key: value directive:

Directive Effect
gotoolchain: go1.21.0 GOTOOLCHAIN for the scan, setting the toolchain whose standard library govulncheck analyzes
skip: true Skip the case

A line that is neither fails the test, so a mistyped directive can't quietly read as a comment.

Reproduce a test scenario

internal/cmd/repro extracts an internal/testcases/*.txtar scenario into a temp dir:

go run ./internal/cmd/repro -testcase vuln_xtext
cd <dir>
./govulncheck -db file://<dir>/govulncheck-db -json ./... | ./govulncheck-apply

Documentation

Overview

Command govulncheck-apply reads a `govulncheck -json` stream on stdin and applies the identified fixes to the `go.mod`s in your working directory.

govulncheck -json ./... | go tool github.com/netflix-skunkworks/govulncheck-apply

Copyright 2026 Netflix, Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Directories

Path Synopsis
Package internal holds the testcases/*.txtar scenarios and the code that reads them, shared by the test harness and the repro command.
Package internal holds the testcases/*.txtar scenarios and the code that reads them, shared by the test harness and the repro command.
cmd/repro command
Command repro sets up a testcases/*.txtar scenario in a temp directory so you can run govulncheck-apply against it by hand, outside the test harness.
Command repro sets up a testcases/*.txtar scenario in a temp directory so you can run govulncheck-apply against it by hand, outside the test harness.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL