Skip to content

Repository files navigation

.github

Centralized configurations and reusable GitHub Actions workflows for the gofiber organization.

Reusable workflows

Each workflow can be consumed from other repositories with:

jobs:
  example:
    uses: gofiber/.github/.github/workflows/<workflow-file>@main
    # with: ...
    # secrets: ...

go-lint

Runs golangci-lint with the same defaults as the gofiber repositories.

  • Inputs: go-version (default 1.25.x), working-directory (default .), golangci-version (default v2.5.0), config-path (default .github/.golangci.yml), config-repository (default gofiber/.github), config-ref (default main), use-shared-config (default true).

go-test

Runs gotestsum across the Go/test matrix used in gofiber/fiber by default.

  • Inputs: go-versions JSON array (default ["1.25.x"]), platforms JSON array (default ["ubuntu-latest", "windows-latest", "macos-latest"]), working-directory (default .), package-pattern (default ./...), codecov-flags (default unittests), codecov-slug (default ${{ github.repository }}), enable-codecov (default true), enable-repeated (default true).
  • Secrets: optional codecov-token when publishing coverage.

markdown-check

Runs markdownlint-cli2 against Markdown files.

  • Inputs: globs (newline-separated list) and optional config path. Defaults match the organization markdown workflow.

release-drafter

Runs Release Drafter with a configurable config path fetched from this repo by default.

  • Inputs: config-path (default .github/release-drafter.yml), config-repository (default gofiber/.github), config-ref (default main).
  • Secrets: optional release-token with contents:write permission; otherwise uses the default token.

auto-labeler

Applies labels from the shared configuration in this repository using the gofiber/multi-labeler action. The base configuration captures labels common to gofiber/contrib and gofiber/fiber; repository-specific rules (for example, versioned branches in gofiber/fiber) should be added via a repo-local labeler.yml that extends this shared file.

  • Inputs: config-path (default .github/labeler.yml), config-repository (default gofiber/.github), config-ref (default main).
  • Secrets: optional github-token with pull_requests:write and issues:write; otherwise uses the default token.

dependabot-automerge

Automatically enables auto-merge on Dependabot pull requests.

  • Inputs: match_pattern (regex of status check names to wait for, default test|discover|go), wait-delay (seconds before the first poll, default 60).
  • Secrets: github-token with pull_requests:write and contents:write. Declared optional, but a PAT is required in practice: the Actions bot may not approve a pull request, so the default token cannot get the merge through.
  • Only runs when the actor is dependabot[bot].
  • Merges minor and patch updates, plus github_actions majors - but not for four glue actions, and not in this repository, whose reusable workflows no pull request check here exercises.

security-golang

Runs Go security checks.

  • Inputs: run-govulncheck (default true), run-codeql (default false), working-directory (default .), go-version (default stable).
  • CodeQL publishes results to code scanning when enabled.

sync-docs

Pushes documentation (or any directory) from the caller repository to another repository.

  • Inputs: source-path, destination-repo, optional destination-branch, destination-path, commit-message, git-user-name, git-user-email.
  • Secrets: destination-token with push access to the destination repository.

pr-command

Runs a repository command when a maintainer comments a slash command on a pull request, then pushes whatever the command changed back onto the PR branch. Only the command and the script belong to the caller; the comment parsing, the permission gate, the reactions, the commit and the result comment live here. Unlike the other workflows in this repository a caller brings its own on:, concurrency: and permissions:, and is called pr-commands.yml because one caller can host several commands:

name: PR Commands

on:
  issue_comment:
    types: [created]
  pull_request_target:
    types: [opened]

permissions:
  contents: write
  pull-requests: write

jobs:
  hint:
    if: github.event_name == 'pull_request_target'
    uses: gofiber/.github/.github/workflows/pr-command-hint.yml@main
    with:
      hint: '`/tidy` runs go mod tidy on this branch'

  tidy:
    if: github.event_name == 'issue_comment'
    # One group per command and pull request, so a second /tidy waits instead of
    # racing the first one's push.
    concurrency:
      group: ${{ github.workflow }}-tidy-${{ github.event.issue.number }}
      cancel-in-progress: false
    uses: gofiber/.github/.github/workflows/pr-command.yml@main
    with:
      command: tidy
      paths: go.mod go.sum
      commit-message: 'chore: go mod tidy'
      run: go mod tidy
  • Inputs: command (the slash command without the slash), run (the script executed on the pull request head, with the words typed after the command in $ARGS), commit-message, paths (space separated pathspecs the command may change, default .), runs-on (default ubuntu-latest), go-version (empty takes it from go.mod, none skips the Go setup), timeout-minutes (default 30).
  • Secrets: optional push-token, a PAT with write access to the pull request head (gofiber/utils and gofiber/fiber pass the org's PR_TOKEN). Without it a fork branch cannot be pushed to and the patch is attached to the run instead, and because a push made with GITHUB_TOKEN creates no workflow run, the repository's checks keep showing the commit before it. Only the pushing job sees the PAT, and that job runs nothing from the pull request.
  • The command has to sit on a line of its own in the conversation tab, a review thread is not an issue_comment, and the commenter needs write, maintain or admin on the repository. Every run a maintainer starts answers with one comment; a comment from someone without write access only gets a reaction.
  • The words after the command reach $ARGS only if they are made of [A-Za-z0-9._,=:/+ -]; anything else is refused with a comment naming the reason.
  • issue_comment always runs the copy of the workflow on the default branch, so a caller cannot be tried out from the pull request that adds it: merge it first.
  • pr-command-hint.yml (the hint job above) appends one small line naming the commands to the description of every pull request a person opens. It sits apart from pr-command.yml so a repository with several commands still gets a single line. The line lands in the description only, never in a commit: neither repository takes the description into its squash message.
  • In use: gofiber/utils for /bench-readme and /bench-readme-amd64, gofiber/fiber for /generate.

Shared configuration

This repository also stores configuration that should remain identical across gofiber projects:

  • .github/release-drafter.yml: Release Drafter template and categories used by the release-drafter workflow.
  • .github/labeler.yml: Label mappings used by the auto-labeler workflow.
  • .github/.golangci.yml: golangci-lint rules used by the go-lint workflow.

When consuming the corresponding workflows, the shared configuration is automatically fetched from this repository unless you override the inputs.

About

Global configurations for the Gofiber GitHub organization

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages