Skip to content

Bump go.mongodb.org/mongo-driver/v2 from 2.8.0 to 2.8.2 in the go-minor-patch group #275

Bump go.mongodb.org/mongo-driver/v2 from 2.8.0 to 2.8.2 in the go-minor-patch group

Bump go.mongodb.org/mongo-driver/v2 from 2.8.0 to 2.8.2 in the go-minor-patch group #275

Workflow file for this run

name: CI
on:
push:
pull_request:
# Read-only by default; the jobs that need more ask for it explicitly.
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
services:
# Enables the MongoDB-backed tests, which are skipped without it.
mongo:
image: mongo:8
ports:
- 27017:27017
options: >-
--health-cmd "mongosh --quiet --eval 'db.runCommand({ping:1}).ok'"
--health-interval 10s
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Check formatting
run: |
unformatted=$(gofmt -l .)
if [ -n "$unformatted" ]; then
echo "These files need gofmt:"
echo "$unformatted"
exit 1
fi
- name: Vet
run: go vet ./...
- name: Test
env:
MONGO_TEST_URL: mongodb://localhost:27017
run: go test -race ./...
- name: Build
run: go build ./...
publish:
runs-on: ubuntu-latest
needs: test
if: github.ref == 'refs/heads/main' || github.ref == 'refs/heads/dev'
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: ghcr.io/${{ github.repository }}
# latest on main, dev on dev — unchanged from the previous pipeline,
# so nothing downstream needs reconfiguring. The sha- tag is new: it
# makes a rollback a docker pull of a known digest rather than
# archaeology through the registry.
tags: |
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }}
type=raw,value=dev,enable=${{ github.ref == 'refs/heads/dev' }}
type=sha,prefix=sha-,format=short
- uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: VERSION=${{ github.sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
deploy:
runs-on: ubuntu-latest
needs: publish
if: github.ref == 'refs/heads/main' || github.ref == 'refs/heads/dev'
# Each environment holds its own DEPLOY_UPDATE_WEBHOOK and
# DEPLOY_UPDATE_TOKEN: main deploys itemize.no, dev deploys
# dev.itemize.no. Both point at that host's watchtower HTTP API
# (POST /v1/update behind Caddy), which restarts only the containers
# whose image actually changed.
environment: ${{ github.ref == 'refs/heads/main' && 'production' || 'development' }}
steps:
- name: Trigger redeploy
env:
URL: ${{ secrets.DEPLOY_UPDATE_WEBHOOK }}
TOKEN: ${{ secrets.DEPLOY_UPDATE_TOKEN }}
# -f so a failing webhook fails the job. The previous pipeline used
# `curl -i`, which reported success even when the deploy never fired.
run: |
curl -fsS -X POST -H "Authorization: Bearer $TOKEN" "$URL"