Skip to content

Commit 70ffdab

Browse files
committed
fix(ci): run govulncheck on fixed toolchain
1 parent e448439 commit 70ffdab

1 file changed

Lines changed: 69 additions & 5 deletions

File tree

‎.github/workflows/build.yml‎

Lines changed: 69 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,73 @@ name: build
22
on: [push, pull_request]
33

44
jobs:
5+
govulncheck:
6+
runs-on: ubuntu-latest
7+
env:
8+
GH_PAT: "${{ secrets.PERSONAL_ACCESS_TOKEN }}"
9+
GOTOOLCHAIN: local
10+
steps:
11+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
12+
# The reusable charmbracelet/meta govulncheck job always reads go.mod.
13+
# Keep the module baseline at Go 1.25.0, but run the scanner with Go 1.26.4
14+
# so it uses a fixed standard library.
15+
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
16+
with:
17+
go-version: "1.26.4"
18+
cache: true
19+
check-latest: true
20+
- run: |
21+
git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmbracelet".insteadOf "https://github.com/charmbracelet"
22+
git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmcli".insteadOf "https://github.com/charmcli"
23+
if: env.GH_PAT != ''
24+
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
25+
- run: go mod tidy
26+
- run: govulncheck ./...
27+
528
build:
6-
uses: charmbracelet/meta/.github/workflows/build.yml@main
7-
with:
8-
go-version: "1.26.4"
9-
secrets:
10-
gh_pat: "${{ secrets.PERSONAL_ACCESS_TOKEN }}"
29+
strategy:
30+
matrix:
31+
os: [ubuntu-latest, macos-latest, windows-latest]
32+
runs-on: ${{ matrix.os }}
33+
env:
34+
GO111MODULE: "on"
35+
GH_PAT: "${{ secrets.PERSONAL_ACCESS_TOKEN }}"
36+
steps:
37+
- name: Checkout code
38+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
39+
- run: |
40+
git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmbracelet".insteadOf "https://github.com/charmbracelet"
41+
git config --global url."https://${{ secrets.PERSONAL_ACCESS_TOKEN }}@github.com/charmcli".insteadOf "https://github.com/charmcli"
42+
if: env.GH_PAT != ''
43+
- name: Install Go
44+
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
45+
with:
46+
go-version-file: go.mod
47+
cache: true
48+
- name: Tidy Go modules
49+
run: go mod tidy
50+
- name: Check for changes
51+
run: git diff --exit-code
52+
- name: Build
53+
run: go build ./...
54+
- name: Test
55+
run: go test ./...
56+
57+
dependabot:
58+
needs: [build, govulncheck]
59+
runs-on: ubuntu-latest
60+
permissions:
61+
pull-requests: write
62+
contents: write
63+
if: ${{ github.actor == 'dependabot[bot]' && github.event_name == 'pull_request' }}
64+
steps:
65+
- id: metadata
66+
uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
67+
with:
68+
github-token: "${{ secrets.GITHUB_TOKEN }}"
69+
- run: |
70+
gh pr review --approve "$PR_URL"
71+
gh pr merge --squash --auto "$PR_URL"
72+
env:
73+
PR_URL: ${{ github.event.pull_request.html_url }}
74+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)