Repository navigation
feat(go-ci): warm the build cache before linting, and let callers set the timeout #38
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Self Test | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| actionlint: | |
| name: Lint workflows | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Set up Go | |
| uses: actions/setup-go@v7 | |
| with: | |
| go-version: '1.26' | |
| cache: false | |
| - name: Install actionlint | |
| run: go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 | |
| - name: Run actionlint | |
| run: actionlint -color | |
| fixtures: | |
| name: Fixtures build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| strategy: | |
| matrix: | |
| fixture: [fixture-lib, fixture-partial-make, fixture-nodeps] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Set up Go | |
| uses: actions/setup-go@v7 | |
| with: | |
| go-version: '1.26' | |
| cache-dependency-path: testdata/${{ matrix.fixture }}/go.mod | |
| - name: Test fixture | |
| working-directory: testdata/${{ matrix.fixture }} | |
| run: go test ./... | |
| smoke-fallback: | |
| name: Smoke — no Makefile | |
| permissions: | |
| contents: read | |
| security-events: write | |
| uses: ./.github/workflows/go-ci.yml | |
| with: | |
| working-directory: testdata/fixture-lib | |
| go-versions: '["1.26"]' | |
| os: '["ubuntu-latest","windows-latest"]' | |
| coverage: true | |
| skip-security: false | |
| smoke-partial-make: | |
| name: Smoke — Makefile without test-coverage | |
| permissions: | |
| contents: read | |
| security-events: write | |
| uses: ./.github/workflows/go-ci.yml | |
| with: | |
| working-directory: testdata/fixture-partial-make | |
| go-versions: '["1.26"]' | |
| os: '["ubuntu-latest"]' | |
| coverage: true | |
| skip-security: true | |
| smoke-nodeps: | |
| name: Smoke — no dependencies (no go.sum) | |
| permissions: | |
| contents: read | |
| security-events: write | |
| uses: ./.github/workflows/go-ci.yml | |
| with: | |
| working-directory: testdata/fixture-nodeps | |
| go-versions: '["1.26"]' | |
| os: '["ubuntu-latest"]' | |
| skip-security: true | |
| smoke-semantic-release: | |
| name: Smoke — semantic-release dry run | |
| permissions: | |
| contents: write | |
| issues: write | |
| pull-requests: write | |
| uses: ./.github/workflows/semantic-release.yml | |
| with: | |
| dry-run: true | |
| smoke-go-node: | |
| name: Smoke — Go with a Node toolchain | |
| permissions: | |
| contents: read | |
| security-events: write | |
| uses: ./.github/workflows/go-ci.yml | |
| with: | |
| working-directory: testdata/fixture-go-node | |
| go-versions: '["1.26"]' | |
| os: '["ubuntu-latest"]' | |
| node-version: '22' | |
| npm-global-packages: 'esbuild@0.28.1' | |
| # The fixture's Makefile `test` target exits 1 on purpose. Passing here | |
| # proves the probe was genuinely bypassed, not merely that make was absent. | |
| prefer-makefile: false | |
| only-test: true | |
| coverage: false | |
| smoke-rust-make: | |
| name: Smoke — Rust partial Makefile | |
| permissions: | |
| contents: read | |
| uses: ./.github/workflows/rust-ci.yml | |
| with: | |
| working-directory: testdata/fixture-rust-make | |
| skip-audit: false | |
| smoke-rust: | |
| name: Smoke — Rust fallback path | |
| permissions: | |
| contents: read | |
| uses: ./.github/workflows/rust-ci.yml | |
| with: | |
| working-directory: testdata/fixture-rust | |
| skip-audit: false | |
| # A single stable check for branch protection to require. | |
| # | |
| # Requiring the individual jobs does not work here: their check names carry | |
| # matrix values and pinned toolchain versions — "Test (ubuntu-latest, go1.26)", | |
| # "Test (ubuntu / stable)" — so bumping Go or Rust would rename the required | |
| # check, and a required check that never reports blocks every merge silently. | |
| # Two of the nested names even contain unexpanded ${{ matrix.* }} expressions. | |
| # | |
| # This job's name never changes, so protection can require exactly one check | |
| # and still gate on all of them. | |
| gate: | |
| name: Self Test Gate | |
| # always() so the gate still reports when something upstream failed; | |
| # without it this job would be skipped and the check would never arrive. | |
| if: always() | |
| needs: | |
| - actionlint | |
| - fixtures | |
| - smoke-fallback | |
| - smoke-partial-make | |
| - smoke-nodeps | |
| - smoke-semantic-release | |
| - smoke-go-node | |
| - smoke-rust-make | |
| - smoke-rust | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check every gating job succeeded | |
| shell: bash | |
| env: | |
| # Read through env, never interpolated into the script body: a | |
| # ${{ }} value is substituted into the source before bash parses it. | |
| RESULTS: ${{ join(needs.*.result, ',') }} | |
| run: | | |
| set -euo pipefail | |
| echo "upstream results: $RESULTS" | |
| case ",$RESULTS," in | |
| *,failure,*|*,cancelled,*|*,timed_out,*) | |
| echo "Self Test failed — see the job that reported it above." | |
| exit 1 | |
| ;; | |
| esac | |
| echo "All gating jobs passed." >> "$GITHUB_STEP_SUMMARY" |