Repository navigation
Remove Learning Roadmap document to streamline project documentation … #20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Go CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| permissions: | |
| contents: read # Explicit read access to repository code | |
| security-events: write | |
| actions: read | |
| jobs: | |
| # Build verification | |
| build: | |
| name: Build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.24.2" | |
| cache: true | |
| - name: Download dependencies | |
| run: go mod download | |
| - name: Verify dependencies | |
| run: go mod verify | |
| - name: Build application | |
| run: go build -v -o bin/doit ./cmd/doit | |
| - name: Build seeder | |
| run: go build -v -o bin/seed ./cmd/seed | |
| # Tests with coverage | |
| test: | |
| name: Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.24.2" | |
| cache: true | |
| - name: Download dependencies | |
| run: go mod download | |
| - name: Run tests with race detector and coverage | |
| run: go test -v -race -coverprofile=coverage.out -covermode=atomic ./... | |
| - name: Display coverage summary | |
| run: go tool cover -func=coverage.out | |
| # Code generation verification | |
| codegen: | |
| name: Verify Code Generation | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.24.2" | |
| cache: true | |
| - name: Install sqlc | |
| run: go install github.com/sqlc-dev/sqlc/cmd/sqlc@latest | |
| - name: Install mockgen | |
| run: go install go.uber.org/mock/mockgen@latest | |
| - name: Generate sqlc code | |
| run: sqlc generate | |
| - name: Generate mocks | |
| run: ./scripts/generate-mocks.sh | |
| - name: Check for uncommitted changes | |
| run: | | |
| if [[ $(git status --porcelain) ]]; then | |
| echo "❌ Generated code is out of sync. Please run 'make sqlc' and 'make generate-mocks' and commit." | |
| git diff | |
| exit 1 | |
| fi | |
| echo "✅ Generated code is up to date" | |
| # Security scanning | |
| security: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.24.2" | |
| cache: true | |
| - name: Run Gosec Security Scanner | |
| uses: securego/gosec@master | |
| with: | |
| args: "-no-fail -fmt sarif -out results.sarif ./..." | |
| - name: Upload SARIF file | |
| uses: github/codeql-action/upload-sarif@v3 | |
| if: always() | |
| with: | |
| sarif_file: results.sarif | |
| # Dependency vulnerability scanning | |
| vuln-check: | |
| name: Vulnerability Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.24.2" | |
| cache: true | |
| - name: Install govulncheck | |
| run: go install golang.org/x/vuln/cmd/govulncheck@latest | |
| - name: Run govulncheck | |
| run: govulncheck ./... | |
| continue-on-error: true |