name: CI on: pull_request: push: tags: - v* branches: - main concurrency: group: ci-${{ github.head_ref || github.ref }} cancel-in-progress: true permissions: contents: read jobs: build: name: ๐Ÿ”จ Build (${{ matrix.go-version }}) strategy: fail-fast: false matrix: go-version: [1.25.x, 1.26.x] runs-on: ubuntu-latest steps: - name: ๐Ÿ“ฅ Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡๏ธ Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ matrix.go-version }} - name: ๐Ÿ”จ Build run: go build -v ./cmd/task test: name: ๐Ÿงช Test (${{ matrix.go-version }}, ${{ matrix.platform }}) strategy: fail-fast: false matrix: go-version: [1.25.x, 1.26.x] platform: [ubuntu-latest, macos-latest, windows-latest] runs-on: ${{ matrix.platform }} steps: - name: ๐Ÿ“ฅ Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡๏ธ Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ matrix.go-version }} - name: โฌ‡๏ธ Setup Task uses: go-task/setup-task@v2 - name: ๐Ÿงช Test run: task test --output group --output-group-begin '::group::{{.TASK}}' --output-group-end '::endgroup::' lint: name: ๐Ÿ” Lint (${{ matrix.go-version }}) strategy: fail-fast: false matrix: go-version: [1.25.x, 1.26.x] runs-on: ubuntu-latest steps: - name: ๐Ÿ“ฅ Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡๏ธ Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ matrix.go-version }} - name: ๐Ÿ” Lint uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: version: v2.13.0 lint-jsonschema: name: ๐Ÿ“‹ Lint JSON Schema runs-on: ubuntu-latest steps: - name: ๐Ÿ“ฅ Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: โฌ‡๏ธ Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: 3.14 - name: โฌ‡๏ธ Install check-jsonschema run: python -m pip install 'check-jsonschema==0.27.3' - name: ๐Ÿ“‹ Validate JSON Schema run: check-jsonschema --check-metaschema website/src/public/next-schema.json website/src/public/schema.json check-latest-content: name: ๐Ÿ“š Check latest content # Pull requests only: the release commit is pushed straight to main and is # the one thing allowed to rewrite these files. if: github.event_name == 'pull_request' runs-on: ubuntu-latest permissions: pull-requests: read steps: - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | // Everything cmd/release overwrites. Adding a file is fine -- that // is how a blog post gets published early -- editing one is not. const generated = (name) => name.startsWith('website/src/latest/') || name === 'website/src/public/schema.json' || name === 'website/src/public/schema-taskrc.json' || name === 'website/.vitepress/sidebar/latest.ts' const files = await github.paginate( github.rest.pulls.listFiles, { pull_number: context.issue.number, owner: context.repo.owner, repo: context.repo.repo, per_page: 100, } ) const edited = files.filter( (f) => generated(f.filename) && f.status !== 'added' ) if (edited.length > 0) { core.setFailed( 'These files are generated by cmd/release and would be overwritten at the next release. Update their website/src counterpart instead:\n' + edited.map((f) => f.filename).join('\n') ) } govulncheck: name: ๐Ÿ›ก๏ธ Vulnerabilities runs-on: ubuntu-latest steps: - uses: golang/govulncheck-action@032d45514ae346b1db93c04b0c90b841c370344f # v1.1.0