Skip to content

fix: patch vulnerable dependencies and harden the release workflow - #6

Merged
AlejandroFabianCampos merged 3 commits into
mainfrom
fix/dependency-and-release-hardening
Sep 23, 2026
Merged

AlejandroFabianCampos merged 3 commits into
mainfrom
fix/dependency-and-release-hardening

Conversation

@AlejandroFabianCampos

Copy link
Copy Markdown
Member

Security hardening ahead of making the repository public.

Dependencies

govulncheck reported 11 vulnerabilities reachable from the provider's code. It now reports none.

  • Go 1.26.3 → 1.26.8
  • google.golang.org/grpc v1.79.3 → v1.83.2
  • golang.org/x/net v0.52.0 → v0.59.0, golang.org/x/text v0.36.0 → v0.42.0, plus the golang.org/x modules they pull along

Workflows

  • Every action is pinned to a commit SHA, with the release tag in a trailing comment so Dependabot keeps updating them.
  • The release job runs in the release environment. It requires an approval and only deploys from v* tags.
  • The release job checks out without persisted credentials and builds without the shared Go module cache, so a cache written by a pull request run cannot reach a signed build.
  • GoReleaser is pinned to v2.18.2 in place of the ~> v2 range.

Before the first release

GPG_PRIVATE_KEY and PASSPHRASE are repository secrets. They need to be re-added as release environment secrets and then deleted at repository level; until then, any workflow in the repository can read them.

make test and make lint pass, and actionlint reports nothing.

-AI generated

@AlejandroFabianCampos
AlejandroFabianCampos requested a review from a team as a code owner September 23, 2026 16:44
@AlejandroFabianCampos
AlejandroFabianCampos merged commit 4c64c27 into main Sep 23, 2026
4 checks passed
@AlejandroFabianCampos
AlejandroFabianCampos deleted the fix/dependency-and-release-hardening branch September 25, 2026 14:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants