6 Commits

7 changed files with 364 additions and 0 deletions
+8
View File
@@ -0,0 +1,8 @@
[tool.commitizen]
name = cz_conventional_commits
version = 0.0.1
tag_format = v
update_changelog_on_bump = true
version_files = [
.cz.toml:version
]
+52
View File
@@ -0,0 +1,52 @@
name: Go Format
on:
workflow_call:
inputs:
go-version-file:
description: "Path to go.mod for version resolution"
type: string
default: "go.mod"
run-vet:
description: "Also run go vet"
type: boolean
default: true
jobs:
fmt:
name: gofmt
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Check formatting
run: |
unformatted=$(gofmt -l .)
if [ -n "$unformatted" ]; then
echo "::error::The following files are not gofmt-formatted:"
echo "$unformatted"
echo ""
echo "Run: gofmt -w ."
exit 1
fi
vet:
name: go vet
runs-on: ubuntu-latest
needs: fmt
if: ${{ inputs.run-vet }}
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: go vet
run: go vet ./...
@@ -0,0 +1,61 @@
name: Go Releaser Check
on:
workflow_call:
inputs:
go-version-file:
description: "Path to go.mod for version resolution"
type: string
default: "go.mod"
snapshot-artifact:
description: "Upload snapshot binaries as artifact"
type: boolean
default: false
jobs:
check:
name: goreleaser check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Validate .goreleaser.yaml
uses: goreleaser/goreleaser-action@v6
with:
version: latest
args: check
build:
name: goreleaser build (snapshot)
runs-on: ubuntu-latest
needs: check
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Build snapshot
uses: goreleaser/goreleaser-action@v6
with:
version: latest
args: build --snapshot --clean
- name: Upload snapshot binaries
if: ${{ inputs.snapshot-artifact }}
uses: actions/upload-artifact@v4
with:
name: snapshot-binaries
path: dist/
retention-days: 3
@@ -0,0 +1,35 @@
name: Go Release
on:
workflow_call:
inputs:
go-version-file:
description: "Path to go.mod for version resolution"
type: string
default: "go.mod"
secrets:
GITHUB_TOKEN:
required: true
jobs:
release:
name: goreleaser release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v6
with:
version: latest
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
@@ -0,0 +1,87 @@
name: Go Security
on:
workflow_call:
inputs:
go-version-file:
description: "Path to go.mod for version resolution"
type: string
default: "go.mod"
jobs:
license:
name: licence check (trivy)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Trivy
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- name: Write Trivy config
run: |
{
echo "scan:"
echo " scanners:"
echo " - license"
echo "license:"
echo " forbidden:"
echo " - GPL-2.0"
echo " - GPL-3.0"
echo " - AGPL-3.0"
echo " - SSPL"
echo " restricted:"
echo " - LGPL-2.1"
echo " - LGPL-3.0"
} > /tmp/trivy-license.yaml
- name: Scan licences (full report)
run: |
trivy fs \
--config /tmp/trivy-license.yaml \
--format json \
--output trivy-license-report.json \
--exit-code 0 \
.
- name: Upload licence report
if: always()
uses: actions/upload-artifact@v4
with:
name: trivy-license-report
path: trivy-license-report.json
retention-days: 7
- name: Fail on forbidden licences
run: |
trivy fs \
--config /tmp/trivy-license.yaml \
--severity CRITICAL \
--exit-code 1 \
.
vuln:
name: vulnerability check (govulncheck)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Run govulncheck
run: govulncheck -json ./... > govulncheck-report.json
- name: Upload vulnerability report
if: always()
uses: actions/upload-artifact@v4
with:
name: govulncheck-report
path: govulncheck-report.json
retention-days: 7
+52
View File
@@ -0,0 +1,52 @@
name: Go Test
on:
workflow_call:
inputs:
go-version-file:
description: "Path to go.mod for version resolution"
type: string
default: "go.mod"
run-race:
description: "Enable race detector"
type: boolean
default: true
timeout:
description: "Test timeout (go test -timeout)"
type: string
default: "20m"
coverage:
description: "Upload coverage report as artifact"
type: boolean
default: true
jobs:
test:
name: go test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: ${{ inputs.go-version-file }}
cache: true
- name: Run tests
run: |
ARGS="-timeout ${{ inputs.timeout }}"
if [ "${{ inputs.run-race }}" = "true" ]; then
ARGS="$ARGS -race"
fi
if [ "${{ inputs.coverage }}" = "true" ]; then
ARGS="$ARGS -coverprofile=coverage.out -covermode=atomic"
fi
go test $ARGS ./...
- name: Upload coverage report
if: ${{ inputs.coverage }}
uses: actions/upload-artifact@v4
with:
name: coverage-report
path: coverage.out
retention-days: 7
+69
View File
@@ -0,0 +1,69 @@
# Reusable YAML lint workflow
# Lives in your central workflows repo, e.g.:
# github.com/your-org/.github/.github/workflows/yaml-lint.yml
#
# Call it from any repo:
# uses: your-org/.github/.github/workflows/yaml-lint.yml@main
name: YAML Lint
on:
workflow_call:
inputs:
paths:
description: >
Space-separated list of files/directories to lint.
Supports glob patterns (passed directly to yamllint).
type: string
default: "."
config-file:
description: >
Path to a .yamllint.yml config in the calling repo.
Ignored if config-data is set.
type: string
default: ".yamllint.yml"
config-data:
description: >
Inline yamllint config string. Takes precedence over config-file.
Example: "{extends: default, rules: {line-length: {max: 120}}}"
type: string
default: ""
strict:
description: "Treat warnings as errors (exit 1 on any warning)."
type: boolean
default: false
actionlint:
description: "Also run actionlint on .github/workflows/."
type: boolean
default: true
runner:
description: "Runner label."
type: string
default: "ubuntu-latest"
jobs:
yamllint:
name: yamllint
runs-on: ${{ inputs.runner }}
steps:
- uses: actions/checkout@v4
- name: yamllint
uses: ibiqlik/action-yamllint@v3
with:
file_or_dir: ${{ inputs.paths }}
config_file: ${{ inputs.config-file }}
config_data: ${{ inputs.config-data }}
strict: ${{ inputs.strict }}
actionlint:
name: actionlint
runs-on: ${{ inputs.runner }}
if: ${{ inputs.actionlint }}
steps:
- uses: actions/checkout@v4
- name: actionlint
uses: rhysd/actionlint@v1
with:
ignore: ""