govulncheck fails on master against the 1.25.12 pin with seven stdlib
advisories, all fixed in 1.25.13: GO-2026-5026, GO-2026-5972, GO-2026-6088,
GO-2026-6089, GO-2026-6090, GO-2026-6091 and GO-2026-6218, across crypto/tls,
encoding/asn1, encoding/xml, html/template, net/http and net/url.
Pinning the next patch would only move the problem to the following advisory,
as it did in 76d0cc2c. setup-go accepts a minor-only spec, so "1.25" resolves
to a patch on that line at run time. Staying on 1.25 rather than "stable"
keeps a move to a new minor a deliberate change, matching the `go 1.25.0`
directive in both go.mod files.
check-latest is required with it: by default setup-go uses the patch already
cached on the runner image, so a minor-only spec alone would keep resolving
to whatever that image ships, currently 1.25.12, and the scan would stay red.
146 lines
3.4 KiB
YAML
146 lines
3.4 KiB
YAML
name: release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
pull_request:
|
|
paths:
|
|
- ".github/workflows/release.yml"
|
|
- ".goreleaser.yml"
|
|
- "Makefile"
|
|
- "scripts/**"
|
|
- "backend/**"
|
|
- "frontend/**"
|
|
- "README.md"
|
|
- "LICENSE"
|
|
- "CLAUDE.md"
|
|
- "site/src/docs/getting-started/installation/index.md"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
validate:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
|
|
- name: install go
|
|
uses: actions/setup-go@v6
|
|
with:
|
|
go-version: "1.25"
|
|
check-latest: true
|
|
cache-dependency-path: backend/go.sum
|
|
|
|
- name: install pnpm
|
|
uses: pnpm/action-setup@v6.0.9
|
|
with:
|
|
version: 10.10.0
|
|
run_install: false
|
|
|
|
- name: install node
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version: 20
|
|
cache: "pnpm"
|
|
cache-dependency-path: frontend/pnpm-lock.yaml
|
|
|
|
- name: test and build backend
|
|
run: |
|
|
go test -race -timeout=120s ./...
|
|
go build -race ./...
|
|
working-directory: backend/app
|
|
env:
|
|
TZ: "America/Chicago"
|
|
|
|
- name: test examples
|
|
run: |
|
|
go test -race ./...
|
|
go build -race ./...
|
|
working-directory: backend/_example/memory_store
|
|
env:
|
|
TZ: "America/Chicago"
|
|
|
|
- name: install frontend dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
working-directory: frontend
|
|
env:
|
|
CI: "true"
|
|
|
|
- name: check frontend
|
|
run: |
|
|
pnpm lint
|
|
pnpm type-check
|
|
pnpm test --runInBand
|
|
working-directory: frontend/apps/remark42
|
|
env:
|
|
CI: "true"
|
|
|
|
- name: check goreleaser snapshot
|
|
if: github.event_name == 'pull_request'
|
|
uses: goreleaser/goreleaser-action@v7
|
|
with:
|
|
version: latest
|
|
args: release --snapshot --clean --skip=publish
|
|
env:
|
|
SKIP_PNPM_INSTALL: "true"
|
|
|
|
- name: clean generated release assets
|
|
if: always()
|
|
run: ./scripts/cleanup-release-assets.sh
|
|
|
|
release:
|
|
if: github.event_name == 'push'
|
|
needs: validate
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
|
|
- name: install go
|
|
uses: actions/setup-go@v6
|
|
with:
|
|
go-version: "1.25"
|
|
check-latest: true
|
|
cache-dependency-path: backend/go.sum
|
|
|
|
- name: install pnpm
|
|
uses: pnpm/action-setup@v6.0.9
|
|
with:
|
|
version: 10.10.0
|
|
run_install: false
|
|
|
|
- name: install node
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version: 20
|
|
cache: "pnpm"
|
|
cache-dependency-path: frontend/pnpm-lock.yaml
|
|
|
|
- name: install frontend dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
working-directory: frontend
|
|
env:
|
|
CI: "true"
|
|
|
|
- name: run goreleaser
|
|
uses: goreleaser/goreleaser-action@v7
|
|
with:
|
|
version: latest
|
|
args: release --clean
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
SKIP_PNPM_INSTALL: "true"
|
|
|
|
- name: clean generated release assets
|
|
if: always()
|
|
run: ./scripts/cleanup-release-assets.sh
|