Skip to content

Disable Go module cache in goreleaser check job - #60

Merged
andrew merged 1 commit into
mainfrom
disable-go-cache-goreleaser-check
Oct 1, 2026
Merged

andrew merged 1 commit into
mainfrom
disable-go-cache-goreleaser-check

Conversation

@andrew

@andrew andrew commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

zizmor reports a high-confidence cache-poisoning finding on the setup-go step in the goreleaser-check job in ci.yml: omitting cache leaves module caching enabled in a job that runs goreleaser-action.

The job only runs goreleaser check, which parses .goreleaser.yaml and builds nothing, so the cache saves no time there. release.yml already passes cache: false to the same action.

zizmor .github/workflows/ reports no findings after the change.

The job only runs goreleaser check, which validates .goreleaser.yaml
and builds nothing, so the cache saves no time while leaving the
module cache writable from a job running goreleaser-action.
release.yml already passes cache: false.
@andrew
andrew merged commit 0e4cd71 into main Oct 1, 2026
10 checks passed
@andrew
andrew deleted the disable-go-cache-goreleaser-check branch October 1, 2026 19:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant