This would fit quite well to the testing and quality focused 2.8 milestone. https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck