Skip to content

fix(release): drop cosign --oidc-issuer flag that breaks signing #387

fix(release): drop cosign --oidc-issuer flag that breaks signing

fix(release): drop cosign --oidc-issuer flag that breaks signing #387

Workflow file for this run

name: CI
on:
push:
branches: [main]
paths-ignore:
- '**.md'
- 'docs/**'
- 'web/**'
- 'LICENSE'
- '.github/CODEOWNERS'
pull_request:
paths-ignore:
- '**.md'
- 'docs/**'
- 'web/**'
- 'LICENSE'
- '.github/CODEOWNERS'
workflow_call:
# Cancel in-progress runs for the same branch/PR to avoid wasted resources.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
test:
# Tests run on Ubuntu only. Cross-platform compilation is verified in the
# cross-compile job. Native Windows/macOS testing requires platform-specific
# dependencies (ConPTY, system shells) not available in CI runners.
runs-on: ubuntu-latest
env:
CGO_ENABLED: "0" # Match release build settings
steps:
# Pin actions to full SHA for supply-chain security.
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod
- name: Check formatting (gofmt)
run: |
unformatted=$(gofmt -l .)
if [ -n "$unformatted" ]; then
echo "::error::Files need formatting:"
echo "$unformatted"
exit 1
fi
- name: Check modules tidy
run: |
go mod tidy
git diff --exit-code go.mod go.sum
- name: Check strict formatting (gofumpt)
run: |
go install mvdan.cc/gofumpt@v0.10.0 || { echo "gofumpt install failed, skipping"; exit 0; }
unformatted=$(gofumpt -l .)
if [ -n "$unformatted" ]; then
echo "::error::Files need strict formatting (gofumpt):"
echo "$unformatted"
exit 1
fi
- name: Check dead code
run: |
go install golang.org/x/tools/cmd/deadcode@v0.47.0 || { echo "deadcode install failed, skipping"; exit 0; }
go install github.com/magefile/mage@v1.17.2 || { echo "mage install failed, skipping"; exit 0; }
mage deadcode
- run: go build ./cmd/dispatch/
- name: golangci-lint
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: "v2.12.2"
install-mode: goinstall
- run: go vet ./...
- name: Test with coverage
run: go test -coverprofile=coverage.out ./...
- name: Coverage summary
run: |
echo "### Coverage Summary" >> "$GITHUB_STEP_SUMMARY"
go tool cover -func=coverage.out | tail -1 | awk '{print "Total: " $3}' | tee -a "$GITHUB_STEP_SUMMARY"
- name: Coverage threshold
run: |
COVERAGE=$(go tool cover -func=coverage.out | tail -1 | awk '{print $3}' | sed 's/%//')
echo "Coverage: ${COVERAGE}%"
if [ "$(echo "$COVERAGE < 60" | bc -l)" -eq 1 ]; then
echo "::error::Coverage ${COVERAGE}% is below 60% threshold"
exit 1
fi
- name: Upload coverage
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage
path: coverage.out
- name: Test (race detector)
env:
CGO_ENABLED: "1"
run: go test -race ./... -count=1
- name: govulncheck
run: |
go install golang.org/x/vuln/cmd/govulncheck@v1.5.0
govulncheck ./...
# Verify the binary compiles for all release platforms.
# CGO_ENABLED=0 means cross-compilation is pure Go — no native runners needed.
cross-compile:
runs-on: ubuntu-latest
env:
CGO_ENABLED: "0"
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod
- name: Cross-compile all release targets
run: |
for pair in darwin/amd64 darwin/arm64 windows/amd64 windows/arm64; do
os="${pair%/*}"
arch="${pair#*/}"
echo "Building $os/$arch..."
GOOS=$os GOARCH=$arch go build -o /dev/null ./cmd/dispatch/
done