Bump the ci group with 4 updates #148
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Check | |
| on: | |
| pull_request: | |
| branches: [main] | |
| # Permissions are granted per job (least privilege; the workflow level is | |
| # empty on purpose). A reusable workflow cannot exceed its caller job's grant. | |
| jobs: | |
| # Multi-module gate through the shared go-check.yml: the Makefile fans | |
| # tidy/fmt/vet/lint/test out per module (so the reusable lint job, which | |
| # assumes a single root module, stays off), the git diff catches a PR | |
| # pushed without tidy/fmt, and make coverage merges the per-module | |
| # profiles into the coverage.out artifact sonarqube.yml expects. | |
| go-check: | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| uses: duynhlab/gha-workflows/.github/workflows/go-check.yml@54fd20d46fd99b5fb85e6029247fcaba865c1481 # main # main | |
| with: | |
| command-test: 'make test TAGS=integration && git diff --exit-code && make coverage' | |
| gomod-path: 'obsx/go.mod' # any module works: all pin the same go directive | |
| cache-dependency-path: '**/go.sum' | |
| lint: false # lint runs per module inside make test | |
| # Protobuf contract checks for the gRPC modules under proto/. | |
| # Lints the .proto style and fails the PR on a backward-incompatible change. | |
| buf: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: bufbuild/buf-action@85aebf73123b5c15fd5528aaecbf9129cddf7fa7 # v1.6.0 | |
| with: | |
| lint: true | |
| format: true | |
| breaking: true | |
| breaking_against: 'https://github.com/duynhlab/pkg.git#branch=main' | |
| # Don't post a PR comment: it needs pull-requests:write (and fails on | |
| # fork PRs). The lint/format/breaking checks still gate the PR. | |
| pr_comment: false | |
| # Platform semantic-convention registry (ADR-076): resolves semconv/ against | |
| # the pinned upstream conventions, runs the Rego namespace/unit/stability | |
| # policies, and fails when the generated Go constants drifted from it. | |
| semconv: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - run: make semconv-lockstep | |
| - run: make semconv-check | |
| - run: make semconv-generated-check | |
| sonar: | |
| needs: go-check | |
| permissions: | |
| contents: read | |
| pull-requests: read # sonarqube.yml's job requests this | |
| uses: duynhlab/gha-workflows/.github/workflows/sonarqube.yml@54fd20d46fd99b5fb85e6029247fcaba865c1481 # main # main | |
| with: | |
| project-key: 'duynhlab_pkg' | |
| organization: 'duynhlab' | |
| fail-on-quality-gate: false | |
| secrets: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} |