@@ -2,9 +2,73 @@ name: build
22on : [push, pull_request]
33
44jobs :
5+ govulncheck :
6+ runs-on : ubuntu-latest
7+ env :
8+ GH_PAT : " ${{ secrets.PERSONAL_ACCESS_TOKEN }}"
9+ GOTOOLCHAIN : local
10+ steps :
11+ - uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
12+ # The reusable charmbracelet/meta govulncheck job always reads go.mod.
13+ # Keep the module baseline at Go 1.25.0, but run the scanner with Go 1.26.4
14+ # so it uses a fixed standard library.
15+ - uses : actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
16+ with :
17+ go-version : " 1.26.4"
18+ cache : true
19+ check-latest : true
20+ - run : |
21+ git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmbracelet".insteadOf "https://github.com/charmbracelet"
22+ git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmcli".insteadOf "https://github.com/charmcli"
23+ if: env.GH_PAT != ''
24+ - run : go install golang.org/x/vuln/cmd/govulncheck@latest
25+ - run : go mod tidy
26+ - run : govulncheck ./...
27+
528 build :
6- uses : charmbracelet/meta/.github/workflows/build.yml@main
7- with :
8- go-version : " 1.26.4"
9- secrets :
10- gh_pat : " ${{ secrets.PERSONAL_ACCESS_TOKEN }}"
29+ strategy :
30+ matrix :
31+ os : [ubuntu-latest, macos-latest, windows-latest]
32+ runs-on : ${{ matrix.os }}
33+ env :
34+ GO111MODULE : " on"
35+ GH_PAT : " ${{ secrets.PERSONAL_ACCESS_TOKEN }}"
36+ steps :
37+ - name : Checkout code
38+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
39+ - run : |
40+ git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmbracelet".insteadOf "https://github.com/charmbracelet"
41+ git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmcli".insteadOf "https://github.com/charmcli"
42+ if: env.GH_PAT != ''
43+ - name : Install Go
44+ uses : actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
45+ with :
46+ go-version-file : go.mod
47+ cache : true
48+ - name : Tidy Go modules
49+ run : go mod tidy
50+ - name : Check for changes
51+ run : git diff --exit-code
52+ - name : Build
53+ run : go build ./...
54+ - name : Test
55+ run : go test ./...
56+
57+ dependabot :
58+ needs : [build, govulncheck]
59+ runs-on : ubuntu-latest
60+ permissions :
61+ pull-requests : write
62+ contents : write
63+ if : ${{ github.actor == 'dependabot[bot]' && github.event_name == 'pull_request' }}
64+ steps :
65+ - id : metadata
66+ uses : dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
67+ with :
68+ github-token : " ${{ secrets.GITHUB_TOKEN }}"
69+ - run : |
70+ gh pr review --approve "$PR_URL"
71+ gh pr merge --squash --auto "$PR_URL"
72+ env:
73+ PR_URL: ${{ github.event.pull_request.html_url }}
74+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
0 commit comments