Skip to content

fix: use storage.ErrNotFound sentinel for consistent 404 across backends #373

fix: use storage.ErrNotFound sentinel for consistent 404 across backends

fix: use storage.ErrNotFound sentinel for consistent 404 across backends #373

Workflow file for this run

name: Test
on:
push:
branches: ["*"]
pull_request:
branches: ["*"]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
security-events: write
actions: read
env:
GO_VERSION_LATEST: "1.25" # Latest version for lint/security
jobs:
test:
name: Test
runs-on: ubuntu-latest
strategy:
matrix:
go-version: ["1.24", "1.25"]
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: ${{ matrix.go-version }}
- name: Download dependencies
run: go mod download
- name: Verify dependencies
run: go mod verify
- name: Run go vet
run: go vet ./...
- name: Run go fmt check
run: |
if [ "$(gofmt -s -l . | wc -l)" -gt 0 ]; then
echo "The following files are not formatted:"
gofmt -s -l .
exit 1
fi
- name: Run tests
run: go test -v -race -coverprofile=coverage.out ./...
- name: Upload coverage reports to Codecov
if: matrix.go-version == '1.25'
uses: codecov/codecov-action@v5
with:
token: ${{ secrets.CODECOV_TOKEN }}
file: ./coverage.out
flags: unittests
name: codecov-umbrella
fail_ci_if_error: false
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: ${{ env.GO_VERSION_LATEST }}
- name: Download dependencies
run: go mod download
- name: Verify module
run: |
go mod verify
go list -m all
- name: Sanity build (exports)
run: go build ./...
- name: golangci-lint
uses: golangci/golangci-lint-action@v8
with:
version: latest
args: --timeout=5m --verbose --max-issues-per-linter=0 --max-same-issues=0
security:
name: Security Scan
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: ${{ env.GO_VERSION_LATEST }}
- name: Run Gosec Security Scanner
run: |
go install github.com/securego/gosec/v2/cmd/gosec@latest
gosec -no-fail -fmt sarif -out results.sarif ./...
gosec -no-fail -fmt json -out results.json ./...
- name: Upload SARIF file
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
continue-on-error: true
- name: Upload security scan results
uses: actions/upload-artifact@v4
with:
name: security-scan-results
path: |
results.sarif
results.json
retention-days: 7
build:
name: Build
runs-on: ubuntu-latest
needs: [test, lint]
strategy:
matrix:
go-version: ["1.24", "1.25"]
goos: [linux]
goarch: [amd64, arm64]
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: ${{ matrix.go-version }}
- name: Build binary
env:
GOOS: ${{ matrix.goos }}
GOARCH: ${{ matrix.goarch }}
CGO_ENABLED: 0
run: |
BINARY_NAME=nclip
VERSION=${GITHUB_REF#refs/tags/}
if [[ $VERSION == refs/* ]]; then
VERSION="dev-${GITHUB_SHA:0:7}"
fi
echo "Building for $GOOS/$GOARCH..."
go build -v \
-ldflags="-s -w -X main.version=${VERSION} -X main.buildTime=$(date -u +%Y-%m-%dT%H:%M:%SZ) -X main.gitCommit=${GITHUB_SHA:0:7}" \
-o "dist/${BINARY_NAME}_${GOOS}_${GOARCH}" \
.
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: nclip-${{ matrix.goos }}-${{ matrix.goarch }}-go${{ matrix.go-version }}
path: dist/
retention-days: 7