sk Skill · johnqtcg
go-dependency-audit
Go dependency audit specialist for CVE scanning (govulncheck), license risk triage, outdated dependency detection, upgrade impact analysis, and supply chain security. ALWAYS use when auditing go.mod dependencies, running govulncheck, checking license compatibility, planning dependency upgrades, or investigating supply chain risks in Go projects. Read-only by default — emits a remediation plan instead of mutating…
Open on skills.sh ↗read 2026-09-16
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 30
jsonPython
- Host repository
- johnqtcg/awesome-skills
- Allowed tools
- Read, Grep, Glob, Bash(govulncheck*), Bash(GOWORK=off govulncheck*), Bash(go version*), Bash(go env GO*), Bash(go list -mod=readonly*), Bash(go mod graph*), Bash(go mod verify*), Bash(go mod why*), Bash(go mod edit -json*), Bash(go mod tidy -diff*), Bash(go -C * list -mod=readonly*), Bash(go -C * mod graph*), Bash(go -C * mod verify*), Bash(go -C * mod why*), Bash(go -C * mod edit -json*), Bash(go -C * mod tidy -diff*), Bash(GOWORK=off go -C * list -mod=readonly*), Bash(GOWORK=off go list -mod=readonly*), Bash(go-licenses check*), Bash(go-licenses report*), Bash(go-licenses help*), Bash(GOWORK=off go-licenses check*), Bash(GOWORK=off go-licenses report*), Bash(trivy fs*), Bash(nancy sleuth*), Bash(jq -s*), Bash(jq -rs*)
- Host stars
- 30
- Host language
- Python