Nov. 9, 2022, 1:33 p.m. | Julian Cantillo

DEV Community dev.to




What is govuln?


govuln is a new vulnerability database for looking your code for vulnerable packages and prevent supply chain attacks





How to install the govulncheck cli


govulncheck is the command line inferface for interacting with the database and checking your code against it, install it with the following command:



go install golang.org/x/vuln/cmd/govulncheck@latest


Then run it in your project as follows:



govulncheck .


It will search in your dependencies for vulnerable packages. Here is an example of the output:



govulncheck …

database go golang security todayilearned vuln vulnerability vulnerability database

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Cloud Security Engineer

@ Pacific Gas and Electric Company | Oakland, CA, US, 94612

Penetration Tester (Level 2)

@ Verve Group | Pune, Mahārāshtra, India

Senior Security Operations Engineer (Azure)

@ Jamf | US Remote

(Junior) Cyber Security Consultant IAM (m/w/d)

@ Atos | Berlin, DE, D-13353