Skip to content

ci: pin github actions to commit shas and declare workflow permissions #819

ci: pin github actions to commit shas and declare workflow permissions

ci: pin github actions to commit shas and declare workflow permissions #819

Workflow file for this run

name: CI
on:
push:
branches:
- v3
- v2
paths-ignore:
- '**.md'
- '**.bazel'
- 'WORKSPACE'
pull_request:
branches:
- main
- v3
- v2
paths-ignore:
- '**.md'
- '**.bazel'
- 'WORKSPACE'
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
permissions:
contents: read
jobs:
build:
name: Build
strategy:
matrix:
go: [ 'stable', '1.23.x' ]
os: [ ubuntu-latest ]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0
- name: Setup Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: ${{ matrix.go }}
cache: true
cache-dependency-path: go.sum
- name: Format
run: diff -u <(echo -n) <(go fmt $(go list ./...))
- name: Test
run: go run gotest.tools/gotestsum@latest -f testname -- ./... -race -count=1 -coverprofile=coverage.txt -covermode=atomic -coverpkg=./... -shuffle=on
- name: Upload coverage to Codecov
if: ${{ matrix.os == 'ubuntu-latest' && matrix.go == 'stable' }}
uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0
with:
token: ${{ secrets.CODECOV_TOKEN }}
file: ./coverage.txt
flags: unittests