# Forgejo Actions CI — verification only (vet, test, build). # Build and push happens in build.yaml on main push. # # Path is .gitea/workflows/, not .forgejo/workflows/ or .github/workflows/. # Verified live against this instance (Forgejo 1.27.0, forgejo.riotpiao.com) # on 2026-08-21: a .forgejo/workflows/*.yaml file never creates an action_run # row on push, not once, for any repo -- confirmed both from application logs # (silent, no error) and directly in the action_run table. A .gitea/workflows # file with an identical job spec fires immediately. .github/workflows also # gets scanned (that's how the old, dead ubuntu-latest CI on this repo and on # kmsvc-manage both got action_run rows despite matching no runner) -- so # .forgejo/workflows/ specifically appears unsupported on this instance/version, # not workflow detection being off in general. # # runs-on: docker matches the only label the cluster runner declares. name: CI on: push: branches: [main] pull_request: branches: [main] jobs: verify: name: Test, vet, build runs-on: docker container: image: golang:1.25-bookworm steps: # actions/checkout@v4 is a JS action -- Forgejo Actions execs it with # `node`, which golang:1.25-bookworm doesn't ship. Without this the # checkout step fails with "exec: node: executable file not found in # $PATH" before any of the job's own steps run. Same fix already in use # in kmsvc-manage's ci.yaml; carried over here. - name: install node (required by JS-based actions) run: apt-get update && apt-get install -y --no-install-recommends nodejs ca-certificates git - uses: actions/checkout@v4 - name: go vet run: go vet ./... # The race detector needs cgo, so this cannot run with CGO_ENABLED=0. - name: go test -race run: go test ./... -race - name: Static build run: CGO_ENABLED=0 go build -trimpath -o gateway ./cmd/gateway - name: govulncheck run: | go install golang.org/x/vuln/cmd/govulncheck@latest govulncheck ./... continue-on-error: true