# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner). # Actions come from the gitea.com mirrors; every tool is installed with the Go # toolchain from its module. The same checks run on any machine with # scripts/check.sh, which is the gate while no runner is available. name: ci on: push: branches: [main] pull_request: jobs: test: name: test (Go ${{ matrix.go }}) strategy: fail-fast: false matrix: # Add windows or macos runner labels here when such runners exist. go: [stable, oldstable] runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: ${{ matrix.go }} - run: go mod verify - run: go vet ./... - run: go test -race -count=1 ./... coverage: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - name: at least 90 % in codec, capsule, accesskey, datekey and agewrap run: | set -euo pipefail for pkg in codec capsule accesskey datekey agewrap; do pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p') echo "$pkg: $pct%" awk -v p="$pct" 'BEGIN { exit !(p >= 90) }' done lint: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.14.0 - run: golangci-lint run - name: gosec (advisory) continue-on-error: true run: golangci-lint run --enable-only gosec vuln: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... fuzz-short: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - name: every parser, 20 s each run: ./scripts/fuzz.sh 20s interop: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - name: official age and tle command-line tools run: | go install filippo.io/age/cmd/age@v1.3.2 go install github.com/drand/tlock/cmd/tle@v1.2.0 go test -tags interop -count=1 -v ./capsule -run Interop sbom: runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json - uses: https://gitea.com/actions/upload-artifact@v4 with: name: sbom path: sbom.cdx.json fixtures: name: vectors reproduce and fixtures are frozen runs-on: ubuntu-latest steps: - uses: https://gitea.com/actions/checkout@v4 - uses: https://gitea.com/actions/setup-go@v5 with: go-version: stable - run: | go run ./internal/testkit/genfixtures -out testdata git diff --exit-code testdata