From edff257861690422310cf0626799ba3a4194584b Mon Sep 17 00:00:00 2001 From: Ulzii Otgonbaatar Date: Mon, 4 May 2026 14:37:19 -0600 Subject: [PATCH] ci: add centralized vuln remediation workflow Co-authored-by: Cursor --- .github/workflows/vuln-remediation.yml | 17 +++++++++++++++++ socket.yml | 1 + 2 files changed, 18 insertions(+) create mode 100644 .github/workflows/vuln-remediation.yml create mode 100644 socket.yml diff --git a/.github/workflows/vuln-remediation.yml b/.github/workflows/vuln-remediation.yml new file mode 100644 index 0000000..22ee065 --- /dev/null +++ b/.github/workflows/vuln-remediation.yml @@ -0,0 +1,17 @@ +name: Vulnerability Remediation + +on: + schedule: + - cron: '0 3 * * 3' + workflow_dispatch: + +permissions: + contents: write + pull-requests: write + +jobs: + remediate: + uses: kernel/security-workflows/.github/workflows/vuln-remediation.yml@main + with: + go-version-file: 'go.mod' + secrets: inherit diff --git a/socket.yml b/socket.yml new file mode 100644 index 0000000..22817d2 --- /dev/null +++ b/socket.yml @@ -0,0 +1 @@ +version: 2