Skip to content

ci: harden GitHub Actions permissions, add job timeouts, concurrency and coverage reporting #3892

ci: harden GitHub Actions permissions, add job timeouts, concurrency and coverage reporting

ci: harden GitHub Actions permissions, add job timeouts, concurrency and coverage reporting #3892

Workflow file for this run

name: CI
on:
pull_request:
push:
branches:
- main
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
quality:
name: Code Quality & Lint
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
with:
persist-credentials: false
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.3.0
with:
go-version-file: go.mod
cache: true
- name: Check formatting
shell: bash
run: |
unformatted="$(gofmt -l .)"
if [ -n "$unformatted" ]; then
echo "::error::gofmt needed on:" >&2
echo "$unformatted" >&2
exit 1
fi
- name: Vet
run: go vet ./...
- name: deadcode (advisory)
continue-on-error: true
run: make deadcode
- name: golangci-lint (advisory)
continue-on-error: true
run: make lint-static
test:
name: Unit Tests & Race Detector
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
with:
persist-credentials: false
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.3.0
with:
go-version-file: go.mod
cache: true
- name: Test with race detector & coverage
run: |
go test -race -count=1 -coverprofile=coverage.out -covermode=atomic ./...
- name: Publish coverage summary
if: always()
shell: bash
run: |
if [ -f coverage.out ]; then
total_cov=$(go tool cover -func=coverage.out | grep 'total:' | awk '{print $3}')
echo "### 📊 Test Coverage Summary: **${total_cov}**" >> $GITHUB_STEP_SUMMARY
echo "<details><summary>Coverage per package</summary>" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "| Package | Function | Coverage |" >> $GITHUB_STEP_SUMMARY
echo "| :--- | :--- | :--- |" >> $GITHUB_STEP_SUMMARY
go tool cover -func=coverage.out | grep -v 'total:' | tail -n 25 | while read -r line; do
pkg=$(echo "$line" | awk '{print $1}')
fn=$(echo "$line" | awk '{print $2}')
cov=$(echo "$line" | awk '{print $3}')
echo "| \`$pkg\` | \`$fn\` | **$cov** |" >> $GITHUB_STEP_SUMMARY
done
echo "</details>" >> $GITHUB_STEP_SUMMARY
fi
- name: Upload coverage artifact
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: zero-coverage-report
path: coverage.out
if-no-files-found: warn
smoke:
name: Smoke (${{ matrix.os }})
runs-on: ${{ matrix.os }}
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
os:
- ubuntu-latest
- macos-latest
- windows-latest
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
with:
persist-credentials: false
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.3.0
with:
go-version-file: go.mod
cache: true
- name: Test (Fast Non-Race)
run: go test ./...
- name: Build binary
run: go run ./cmd/zero-release build
- name: Smoke binary
run: go run ./cmd/zero-release smoke
performance:
name: Performance Smoke
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
with:
persist-credentials: false
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.3.0
with:
go-version-file: go.mod
cache: true
- name: Build binary
run: go run ./cmd/zero-release build
- name: Performance smoke
run: |
mkdir -p dist/perf
go run ./cmd/zero-perf-bench --output dist/perf/perf-bench.json --ci
- name: Upload performance report
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: zero-performance-smoke
path: dist/perf/perf-bench.json
if-no-files-found: warn
security:
name: Security & Code Health
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
with:
persist-credentials: false
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.3.0
with:
go-version-file: go.mod
cache: true
- name: govulncheck
run: make vulncheck