A GitHub Action that runs a command in a gVisor sandbox - geomys/sandboxed-step
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.