From 4c08d8d9fda64190bc5201245e461b26007aa0b3 Mon Sep 17 00:00:00 2001 From: unit-adm <314923187+mumtaz6@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:24:46 +0530 Subject: [PATCH] Add CI, CodeQL and Dependabot GitHub Actions run, on every pull request and push to master: - go vet and the tests, with the minimum Go go.mod allows and the latest; - staticcheck's correctness checks; - govulncheck, which fails on vulnerabilities the code reaches; - CodeQL, also weekly. Dependabot proposes Go module and action updates weekly, each ecosystem in one pull request. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/dependabot.yml | 18 ++++++++++++++ .github/workflows/ci.yml | 46 ++++++++++++++++++++++++++++++++++++ .github/workflows/codeql.yml | 26 ++++++++++++++++++++ 3 files changed, 90 insertions(+) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/ci.yml create mode 100644 .github/workflows/codeql.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2b3df9d --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,18 @@ +version: 2 +updates: + # One pull request a week for every Go dependency with an update, so that + # they are tested together. + - package-ecosystem: gomod + directory: / + schedule: + interval: weekly + groups: + go-dependencies: + patterns: ["*"] + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + groups: + github-actions: + patterns: ["*"] diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..5acc3ff --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,46 @@ +name: CI + +on: + push: + branches: [master] + pull_request: + +permissions: + contents: read + +jobs: + test: + name: Test (Go ${{ matrix.go }}) + runs-on: ubuntu-latest + timeout-minutes: 30 + strategy: + fail-fast: false + matrix: + # The minimum go.mod allows, and the latest release. + go: [go.mod, stable] + steps: + - uses: actions/checkout@v7 + - uses: actions/setup-go@v7 + with: + go-version: ${{ matrix.go != 'go.mod' && matrix.go || '' }} + go-version-file: ${{ matrix.go == 'go.mod' && 'go.mod' || '' }} + - run: go vet ./... + - run: go test ./... + + staticcheck: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + - uses: actions/setup-go@v7 + with: + go-version: stable + # The correctness checks only: the style and unused-code checks report + # findings that have not been worked through. + - run: go run honnef.co/go/tools/cmd/staticcheck@2026.2.1 -checks 'SA*' ./... + + govulncheck: + runs-on: ubuntu-latest + steps: + - uses: golang/govulncheck-action@v1 + with: + go-version-input: stable diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..0d91086 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,26 @@ +name: CodeQL + +on: + push: + branches: [master] + pull_request: + schedule: + - cron: '23 4 * * 1' + +permissions: + contents: read + security-events: write + +jobs: + analyze: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + - uses: actions/setup-go@v7 + with: + go-version: stable + - uses: github/codeql-action/init@v4 + with: + languages: go + build-mode: autobuild + - uses: github/codeql-action/analyze@v4