The module is imported as g.activething.com/go/DateKeys, the path the project's Gitea advertises. The .github directory is gone: workflows now live in .gitea/workflows, use the gitea.com action mirrors and install every tool from its Go module; releases go to this Gitea with goreleaser and a key-based cosign signature; Dependabot is replaced by a nightly report of available updates. scripts/check.sh runs the same checks on any machine and is the gate while the server has no runner. SECURITY.md, README and CONTRIBUTING no longer refer to GitHub. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>v0.8.2
parent
3ed9cafe61
commit
13dcca119c
@ -0,0 +1,114 @@
|
||||
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
|
||||
# Actions come from the gitea.com mirrors; every tool is installed with the Go
|
||||
# toolchain from its module. The same checks run on any machine with
|
||||
# scripts/check.sh, which is the gate while no runner is available.
|
||||
name: ci
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: test (Go ${{ matrix.go }})
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# Add windows or macos runner labels here when such runners exist.
|
||||
go: [stable, oldstable]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: ${{ matrix.go }}
|
||||
- run: go mod verify
|
||||
- run: go vet ./...
|
||||
- run: go test -race -count=1 ./...
|
||||
|
||||
coverage:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- name: at least 90 % in codec, capsule, accesskey, datekey and agewrap
|
||||
run: |
|
||||
set -euo pipefail
|
||||
for pkg in codec capsule accesskey datekey agewrap; do
|
||||
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
|
||||
echo "$pkg: $pct%"
|
||||
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
|
||||
done
|
||||
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.14.0
|
||||
- run: golangci-lint run
|
||||
- name: gosec (advisory)
|
||||
continue-on-error: true
|
||||
run: golangci-lint run --enable-only gosec
|
||||
|
||||
vuln:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
||||
|
||||
fuzz-short:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- name: every parser, 20 s each
|
||||
run: ./scripts/fuzz.sh 20s
|
||||
|
||||
interop:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- name: official age and tle command-line tools
|
||||
run: |
|
||||
go install filippo.io/age/cmd/age@v1.3.2
|
||||
go install github.com/drand/tlock/cmd/tle@v1.2.0
|
||||
go test -tags interop -count=1 -v ./capsule -run Interop
|
||||
|
||||
sbom:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json
|
||||
- uses: https://gitea.com/actions/upload-artifact@v4
|
||||
with:
|
||||
name: sbom
|
||||
path: sbom.cdx.json
|
||||
|
||||
fixtures:
|
||||
name: vectors reproduce and fixtures are frozen
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: |
|
||||
go run ./internal/testkit/genfixtures -out testdata
|
||||
git diff --exit-code testdata
|
||||
@ -0,0 +1,58 @@
|
||||
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
|
||||
name: nightly
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "17 3 * * *"
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
integration:
|
||||
name: live Quicknet
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live
|
||||
|
||||
fuzz-long:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 120
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- name: every parser, 10 min each
|
||||
env:
|
||||
FUZZ_MINIMIZE: 10s
|
||||
run: ./scripts/fuzz.sh 10m
|
||||
- name: keep failing inputs
|
||||
if: failure()
|
||||
uses: https://gitea.com/actions/upload-artifact@v4
|
||||
with:
|
||||
name: fuzz-corpus
|
||||
path: "**/testdata/fuzz/**"
|
||||
|
||||
vuln:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
||||
|
||||
updates:
|
||||
name: dependency updates available
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version: stable
|
||||
# Informational. Any change to age, tlock, drand or kyber is reviewed by
|
||||
# hand against SECURITY.md before it is applied.
|
||||
- run: go list -m -u all | grep '\[' || echo "no updates"
|
||||
@ -0,0 +1,29 @@
|
||||
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
|
||||
# Publishes a release on this Gitea server (.goreleaser.yaml, gitea_urls).
|
||||
# Repository secrets: GITEA_TOKEN (a token with write access to releases),
|
||||
# COSIGN_PRIVATE_KEY and COSIGN_PASSWORD (the project's cosign key).
|
||||
name: release
|
||||
|
||||
on:
|
||||
push:
|
||||
tags: ["v*"]
|
||||
|
||||
jobs:
|
||||
release:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: https://gitea.com/actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- uses: https://gitea.com/actions/setup-go@v5
|
||||
with:
|
||||
go-version-file: go.mod
|
||||
- run: go test -count=1 ./...
|
||||
- run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0
|
||||
- run: go install github.com/sigstore/cosign/v2/cmd/cosign@v2.6.5
|
||||
- run: go install github.com/goreleaser/goreleaser/v2@v2.18.2
|
||||
- run: goreleaser release --clean
|
||||
env:
|
||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
||||
@ -1,18 +0,0 @@
|
||||
# Patch updates only. Any change to age, tlock, drand or kyber is reviewed by
|
||||
# hand against SECURITY.md before merging, even when Dependabot proposes it.
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: gomod
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
open-pull-requests-limit: 5
|
||||
labels: [dependencies]
|
||||
ignore:
|
||||
- dependency-name: "*"
|
||||
update-types: ["version-update:semver-major", "version-update:semver-minor"]
|
||||
- package-ecosystem: github-actions
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
labels: [dependencies]
|
||||
@ -1,135 +0,0 @@
|
||||
name: ci
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: test (${{ matrix.os }}, Go ${{ matrix.go }})
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [ubuntu-latest, macos-latest, windows-latest]
|
||||
go: [stable, oldstable]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ matrix.go }}
|
||||
- run: go mod verify
|
||||
- run: go vet ./...
|
||||
- run: go test -race -count=1 ./...
|
||||
|
||||
coverage:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- name: at least 90 % in codec, capsule, accesskey, datekey and agewrap
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
for pkg in codec capsule accesskey datekey agewrap; do
|
||||
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
|
||||
echo "$pkg: $pct%"
|
||||
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
|
||||
done
|
||||
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
|
||||
with:
|
||||
version: v2.14.0
|
||||
- name: gosec (advisory)
|
||||
continue-on-error: true
|
||||
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
|
||||
with:
|
||||
version: v2.14.0
|
||||
args: --enable-only gosec
|
||||
|
||||
vuln:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
||||
|
||||
fuzz-short:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- name: every parser, 20 s each
|
||||
shell: bash
|
||||
run: ./scripts/fuzz.sh 20s
|
||||
|
||||
interop:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- name: official age and tle command-line tools
|
||||
run: |
|
||||
go install filippo.io/age/cmd/age@v1.3.2
|
||||
go install github.com/drand/tlock/cmd/tle@v1.2.0
|
||||
go test -tags interop -count=1 -v ./capsule -run Interop
|
||||
|
||||
sbom:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: sbom
|
||||
path: sbom.cdx.json
|
||||
|
||||
fixtures:
|
||||
name: vectors reproduce and fixtures are frozen
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- run: |
|
||||
go run ./internal/testkit/genfixtures -out testdata
|
||||
git diff --exit-code testdata
|
||||
@ -1,55 +0,0 @@
|
||||
name: nightly
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "17 3 * * *"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
integration:
|
||||
name: live Quicknet
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live
|
||||
|
||||
fuzz-long:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 120
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- name: every parser, 10 min each
|
||||
shell: bash
|
||||
env:
|
||||
FUZZ_MINIMIZE: 10s
|
||||
run: ./scripts/fuzz.sh 10m
|
||||
- name: keep failing inputs
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: fuzz-corpus
|
||||
path: "**/testdata/fuzz/**"
|
||||
|
||||
vuln:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: stable
|
||||
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
||||
@ -1,32 +0,0 @@
|
||||
name: release
|
||||
|
||||
on:
|
||||
push:
|
||||
tags: ["v*"]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
release:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write # publish the GitHub release
|
||||
id-token: write # keyless cosign signature
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version-file: go.mod
|
||||
- run: go test -count=1 ./...
|
||||
- run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0
|
||||
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
||||
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
|
||||
with:
|
||||
version: "~> v2"
|
||||
args: release --clean
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env bash
|
||||
# Local gate: the same checks as .gitea/workflows/ci.yml, for any machine and
|
||||
# for forges without runners. Run it before every push.
|
||||
#
|
||||
# scripts/check.sh # format, modules, vet, race tests, coverage,
|
||||
# # govulncheck, vectors and fixtures
|
||||
# scripts/check.sh 20s # additionally fuzz every parser for 20 s
|
||||
set -euo pipefail
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
fuzz="${1:-}"
|
||||
|
||||
echo "== gofmt"
|
||||
bad=$(gofmt -l .)
|
||||
if [ -n "$bad" ]; then
|
||||
echo "not formatted:"; echo "$bad"; exit 1
|
||||
fi
|
||||
|
||||
echo "== go mod verify"
|
||||
go mod verify
|
||||
|
||||
echo "== go mod tidy leaves go.mod and go.sum unchanged"
|
||||
tmp=$(mktemp -d)
|
||||
cp go.mod go.sum "$tmp"/
|
||||
go mod tidy
|
||||
if ! cmp -s go.mod "$tmp/go.mod" || ! cmp -s go.sum "$tmp/go.sum"; then
|
||||
cp "$tmp"/go.mod "$tmp"/go.sum .
|
||||
rm -rf "$tmp"
|
||||
echo "go mod tidy would change go.mod or go.sum"; exit 1
|
||||
fi
|
||||
rm -rf "$tmp"
|
||||
|
||||
echo "== go vet"
|
||||
go vet ./...
|
||||
|
||||
echo "== go test -race"
|
||||
go test -race -count=1 ./...
|
||||
|
||||
echo "== coverage: at least 90 % in codec, capsule, accesskey, datekey and agewrap"
|
||||
for pkg in codec capsule accesskey datekey agewrap; do
|
||||
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
|
||||
echo "$pkg: $pct%"
|
||||
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
|
||||
done
|
||||
|
||||
echo "== govulncheck"
|
||||
go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
||||
|
||||
echo "== vectors reproduce and fixtures are frozen"
|
||||
go run ./internal/testkit/genfixtures -out testdata
|
||||
git diff --exit-code -- testdata
|
||||
|
||||
if [ -n "$fuzz" ]; then
|
||||
echo "== fuzz every parser for $fuzz"
|
||||
./scripts/fuzz.sh "$fuzz"
|
||||
fi
|
||||
|
||||
echo "all checks passed"
|
||||
Loading…
Reference in new issue