Skip to content

deps(docker): bump node from 24.18.0-alpine to 26.7.0-alpine #935

deps(docker): bump node from 24.18.0-alpine to 26.7.0-alpine

deps(docker): bump node from 24.18.0-alpine to 26.7.0-alpine #935

Workflow file for this run

name: Go CI
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
- name: Enforce fresh-schema / upgrade-migration pairing
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
PUSH_BEFORE_SHA: ${{ github.event.before }}
run: |
if [ -n "$PR_BASE_SHA" ]; then
scripts/check-schema-migration-pairing.sh --range "$PR_BASE_SHA...HEAD"
elif [ -n "$PUSH_BEFORE_SHA" ] && [ "$PUSH_BEFORE_SHA" != "0000000000000000000000000000000000000000" ]; then
scripts/check-schema-migration-pairing.sh --range "$PUSH_BEFORE_SHA...HEAD"
else
scripts/check-schema-migration-pairing.sh --commit HEAD
fi
- name: Set up Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: '.nvmrc'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Install frontend dependencies
run: npm ci
working-directory: frontend
- name: Build frontend
run: npm run build
working-directory: frontend
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
- name: Install golangci-lint
run: make install-golangci-lint
- name: Run Go lint and architecture guards
run: make lint
govulncheck:
name: Go Vulnerability Check
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
- name: Install govulncheck
run: make install-govulncheck
- name: Run govulncheck
run: govulncheck ./...
openapi:
name: OpenAPI Spec Freshness
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
- name: Verify handler annotations parse and produce valid OpenAPI 3.0
run: make openapi-check
# Fails when swag can't parse an annotation, or when the resulting
# spec isn't valid OpenAPI 3.0. Does NOT byte-compare against the
# committed api/openapi.{json,yaml} — that comparison turned out to
# depend on host environment in ways we couldn't pin down. The
# canonical contract is core-tests/TestAPIOpenAPIContract, which
# runs from the core-tests repo via overlay.sh.
build:
name: Build
runs-on: ubuntu-latest
needs: [lint]
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
- name: Set up Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: '.nvmrc'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Install frontend dependencies
run: npm ci
working-directory: frontend
- name: Build frontend
run: npm run build
working-directory: frontend
- name: Build
run: |
go build -ldflags="-s -w" -o windshift .