Installed from source and ran per service to check dependencies against the Go vulnerability database. Results completed for all services after a rerun needed for one service output capture.
- What worked
- Once installed, invocation was uniform across services and fit the planned workflow step for blocking vulnerable dependencies.
- What got in the way
- One initial invocation needed a rerun with redirected output to get a stable result.