Skip to content

feat(go-ci): warm the build cache before linting, and let callers set the timeout #38

feat(go-ci): warm the build cache before linting, and let callers set the timeout

feat(go-ci): warm the build cache before linting, and let callers set the timeout #38

Workflow file for this run

name: Self Test
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
actionlint:
name: Lint workflows
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version: '1.26'
cache: false
- name: Install actionlint
run: go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12
- name: Run actionlint
run: actionlint -color
fixtures:
name: Fixtures build
runs-on: ubuntu-latest
permissions:
contents: read
strategy:
matrix:
fixture: [fixture-lib, fixture-partial-make, fixture-nodeps]
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version: '1.26'
cache-dependency-path: testdata/${{ matrix.fixture }}/go.mod
- name: Test fixture
working-directory: testdata/${{ matrix.fixture }}
run: go test ./...
smoke-fallback:
name: Smoke — no Makefile
permissions:
contents: read
security-events: write
uses: ./.github/workflows/go-ci.yml
with:
working-directory: testdata/fixture-lib
go-versions: '["1.26"]'
os: '["ubuntu-latest","windows-latest"]'
coverage: true
skip-security: false
smoke-partial-make:
name: Smoke — Makefile without test-coverage
permissions:
contents: read
security-events: write
uses: ./.github/workflows/go-ci.yml
with:
working-directory: testdata/fixture-partial-make
go-versions: '["1.26"]'
os: '["ubuntu-latest"]'
coverage: true
skip-security: true
smoke-nodeps:
name: Smoke — no dependencies (no go.sum)
permissions:
contents: read
security-events: write
uses: ./.github/workflows/go-ci.yml
with:
working-directory: testdata/fixture-nodeps
go-versions: '["1.26"]'
os: '["ubuntu-latest"]'
skip-security: true
smoke-semantic-release:
name: Smoke — semantic-release dry run
permissions:
contents: write
issues: write
pull-requests: write
uses: ./.github/workflows/semantic-release.yml
with:
dry-run: true
smoke-go-node:
name: Smoke — Go with a Node toolchain
permissions:
contents: read
security-events: write
uses: ./.github/workflows/go-ci.yml
with:
working-directory: testdata/fixture-go-node
go-versions: '["1.26"]'
os: '["ubuntu-latest"]'
node-version: '22'
npm-global-packages: 'esbuild@0.28.1'
# The fixture's Makefile `test` target exits 1 on purpose. Passing here
# proves the probe was genuinely bypassed, not merely that make was absent.
prefer-makefile: false
only-test: true
coverage: false
smoke-rust-make:
name: Smoke — Rust partial Makefile
permissions:
contents: read
uses: ./.github/workflows/rust-ci.yml
with:
working-directory: testdata/fixture-rust-make
skip-audit: false
smoke-rust:
name: Smoke — Rust fallback path
permissions:
contents: read
uses: ./.github/workflows/rust-ci.yml
with:
working-directory: testdata/fixture-rust
skip-audit: false
# A single stable check for branch protection to require.
#
# Requiring the individual jobs does not work here: their check names carry
# matrix values and pinned toolchain versions — "Test (ubuntu-latest, go1.26)",
# "Test (ubuntu / stable)" — so bumping Go or Rust would rename the required
# check, and a required check that never reports blocks every merge silently.
# Two of the nested names even contain unexpanded ${{ matrix.* }} expressions.
#
# This job's name never changes, so protection can require exactly one check
# and still gate on all of them.
gate:
name: Self Test Gate
# always() so the gate still reports when something upstream failed;
# without it this job would be skipped and the check would never arrive.
if: always()
needs:
- actionlint
- fixtures
- smoke-fallback
- smoke-partial-make
- smoke-nodeps
- smoke-semantic-release
- smoke-go-node
- smoke-rust-make
- smoke-rust
runs-on: ubuntu-latest
steps:
- name: Check every gating job succeeded
shell: bash
env:
# Read through env, never interpolated into the script body: a
# ${{ }} value is substituted into the source before bash parses it.
RESULTS: ${{ join(needs.*.result, ',') }}
run: |
set -euo pipefail
echo "upstream results: $RESULTS"
case ",$RESULTS," in
*,failure,*|*,cancelled,*|*,timed_out,*)
echo "Self Test failed — see the job that reported it above."
exit 1
;;
esac
echo "All gating jobs passed." >> "$GITHUB_STEP_SUMMARY"