subidx/.github/workflows/ci.yml
lakshit verma feae493b0f
ci: add staticcheck lint job
New parallel lint job running Staticcheck (all checks) pinned to
2026.2.1 — the version the codebase was validated against — with the
action pinned by commit SHA like the others. Two findings it surfaced
on first run are already fixed in the parent commit.
2026-08-24 01:13:01 +05:30

57 lines
1.4 KiB
YAML

name: ci
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
steps:
# Pinned by commit SHA: tags are mutable.
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version-file: go.mod
cache: true
- name: Build
run: go build ./...
- name: Vet
run: go vet ./...
- name: Test
run: go test -race -count=1 ./...
- name: Govulncheck
uses: golang/govulncheck-action@032d45514ae346b1db93c04b0c90b841c370344f # v1
with:
go-version-input: ""
go-package: ./...
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version-file: go.mod
cache: true
- name: Staticcheck
uses: dominikh/staticcheck-action@9716614d4101e79b4340dd97b10e54d68234e431 # v1.4.1
with:
checks: all
version: "2026.2.1" # validated locally; bump deliberately
install-go: false # Go comes from setup-go above