.github/workflows: add govulncheck-action

Change-Id: If979e8aa0f8a3c8c08dc8811ed75fd870e1cc6db
Reviewed-on: https://go-review.googlesource.com/c/pkgsite/+/496956
Reviewed-by: Jamal Carvalho <jamal@golang.org>
Reviewed-by: Julie Qiu <julie@golang.org>
Auto-Submit: Julie Qiu <julie@golang.org>
Run-TryBot: Julie Qiu <julie@golang.org>
TryBot-Result: kokoro <noreply+kokoro@google.com>
Reviewed-by: Julie Qiu <julieqiu@google.com>
diff --git a/.github/workflows/govulncheck.yml b/.github/workflows/govulncheck.yml
new file mode 100644
index 0000000..db48a44
--- /dev/null
+++ b/.github/workflows/govulncheck.yml
@@ -0,0 +1,8 @@
+name: Run govulncheck
+on: [push]
+jobs:
+  govulncheck:
+    runs-on: ubuntu-latest
+    steps:
+      - id: govulncheck
+        uses: golang/govulncheck-action@v0.1.0