lib/.github/workflows/push.yml

52 lines
1.4 KiB
YAML

name: CI (lib)
# First-ever CI for go/lib (ADR-KV-014). lib is publicly mirrored on
# code.tnxs.net, so every push and PR gets a build/vet/test job plus a
# gitleaks secret-scan job. lib is a Go library — no Dockerfile, no deploy.
on:
push:
branches: ['**']
pull_request:
defaults:
run:
shell: bash
# Serialize per ref. PR runs cancel superseded validations; branch pushes never cancel.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
test:
runs-on: [self-hosted, Linux]
permissions: { contents: read }
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: stable
- name: go build ./...
run: go build ./...
- name: go vet ./...
run: go vet ./...
- name: go test ./...
run: go test ./...
gitleaks:
runs-on: [self-hosted, Linux]
permissions: { contents: read }
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
- name: gitleaks detect (git history)
run: |
docker run --rm -v "$PWD:/repo" -w /repo zricethezav/gitleaks:latest \
detect --source /repo --redact -v