Repository navigation
131 lines (125 loc) · 4.22 KB
/
Copy pathtest.yml
File metadata and controls
131 lines (125 loc) · 4.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
name: test
on:
workflow_run:
workflows: ["Dependabot PR Check"]
types:
- completed
pull_request:
branches:
- main
# Run on merge to main so the merged result is tested, not just each PR branch
# in isolation. A PR based on stale main can merge into a combination that no
# PR run exercised; this catches that (compile/unit/build only — acceptance
# tests stay PR-gated because they hit live APIs and are slow/flaky).
push:
branches:
- main
# Allow manually triggering CI on a branch
workflow_dispatch: {}
jobs:
unit-test:
runs-on: ubuntu-latest
steps:
- name: Code checkout
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: 1.26.6
- name: Run unit tests
run: go test -short ./pkg/...
# `go test` runs a reduced vet suite (printf, bools, atomic and a few
# more) and only over the packages it tests. The full suite is what
# catches things like sigchanyzer, which found an unbuffered
# signal.Notify channel that had been dropping Ctrl-C on the login
# prompt. Run it over ./... so test/ and tools/ are covered too.
- name: Run go vet
run: go vet ./...
# Keeps the vulnerability scan clean rather than asserting it once. Nothing ran
# govulncheck before, which is how GO-2026-5932 (x/crypto/openpgp, reached only
# through go-github v28's package init) went unnoticed until it was the last
# remaining finding. See #331.
govulncheck:
runs-on: ubuntu-latest
steps:
- name: Code checkout
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: 1.26.6
- name: Run govulncheck
# Pinned rather than @latest: a new govulncheck release could change
# behaviour or fail this job with no change to the repo. Bump
# deliberately. The vulnerability database is still fetched live, so
# newly disclosed issues are picked up without a version bump.
run: |
go install golang.org/x/vuln/cmd/govulncheck@v1.6.0
govulncheck ./...
build-mac:
runs-on: macos-latest
steps:
- name: Code checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: 1.26.6
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v5
with:
version: v2.12.1
args: release --skip=publish --snapshot -f .goreleaser/mac.yml --clean
env:
GITHUB_TOKEN: ${{ secrets.GORELEASER_GITHUB_TOKEN }}
build-linux:
runs-on: ubuntu-latest
if: ${{ github.actor != 'dependabot[bot]' || github.event.workflow_run.conclusion == 'success' }}
env:
# https://goreleaser.com/customization/docker_manifest/
DOCKER_CLI_EXPERIMENTAL: "enabled"
steps:
- name: Code checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Docker Login
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Set up Docker QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: 1.26.6
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v5
with:
version: v2.12.1
args: release --skip=publish --snapshot -f .goreleaser/linux.yml --clean
env:
GITHUB_TOKEN: ${{ secrets.GORELEASER_GITHUB_TOKEN }}
build-windows:
runs-on: windows-latest
steps:
- name: Code checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: 1.26.6
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v5
with:
version: v2.12.1
args: release --skip=publish --snapshot -f .goreleaser/windows.yml --clean
env:
GITHUB_TOKEN: ${{ secrets.GORELEASER_GITHUB_TOKEN }}