name: ci on: push: branches: [main] pull_request: concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: test: runs-on: golang container: image: golang:1.26 env: GOPRIVATE: forgejo.riotpiao.com GOFLAGS: -mod=readonly REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} steps: # actions/checkout is a Node-based action; golang:1.25 has no node on PATH. - name: install node (required by JS-based actions) run: apt-get update && apt-get install -y --no-install-recommends nodejs ca-certificates git - uses: actions/checkout@v4 # kmsvc-proto lives in another private repo on the same Forgejo instance. # GITHUB_TOKEN is auto-injected by Forgejo Actions and has read access to all repos. - name: configure git auth for private module fetch run: | git config --global url."https://oauth2:${REGISTRY_PAT}@forgejo.riotpiao.com".insteadOf "https://forgejo.riotpiao.com" env: REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - name: cache go modules + build cache uses: actions/cache@v4 with: path: | ~/.cache/go-build ~/go/pkg/mod key: go-${{ runner.os }}-${{ hashFiles('go.sum') }} restore-keys: | go-${{ runner.os }}- - name: gofmt run: | fmt_out="$(gofmt -l .)" if [ -n "$fmt_out" ]; then echo "$fmt_out" echo "::error::gofmt found unformatted files, run 'gofmt -w .'" exit 1 fi - name: go vet run: go vet ./... - name: go build run: go build ./... - name: go test run: go test ./... -race -coverprofile=coverage.out - name: coverage summary run: go tool cover -func=coverage.out | tail -1 - name: upload coverage uses: actions/upload-artifact@v4 with: name: coverage path: coverage.out