Bump go.mongodb.org/mongo-driver/v2 from 2.8.0 to 2.8.2 in the go-minor-patch group #275
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| pull_request: | |
| # Read-only by default; the jobs that need more ask for it explicitly. | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| services: | |
| # Enables the MongoDB-backed tests, which are skipped without it. | |
| mongo: | |
| image: mongo:8 | |
| ports: | |
| - 27017:27017 | |
| options: >- | |
| --health-cmd "mongosh --quiet --eval 'db.runCommand({ping:1}).ok'" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Check formatting | |
| run: | | |
| unformatted=$(gofmt -l .) | |
| if [ -n "$unformatted" ]; then | |
| echo "These files need gofmt:" | |
| echo "$unformatted" | |
| exit 1 | |
| fi | |
| - name: Vet | |
| run: go vet ./... | |
| - name: Test | |
| env: | |
| MONGO_TEST_URL: mongodb://localhost:27017 | |
| run: go test -race ./... | |
| - name: Build | |
| run: go build ./... | |
| publish: | |
| runs-on: ubuntu-latest | |
| needs: test | |
| if: github.ref == 'refs/heads/main' || github.ref == 'refs/heads/dev' | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - id: meta | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 | |
| with: | |
| images: ghcr.io/${{ github.repository }} | |
| # latest on main, dev on dev — unchanged from the previous pipeline, | |
| # so nothing downstream needs reconfiguring. The sha- tag is new: it | |
| # makes a rollback a docker pull of a known digest rather than | |
| # archaeology through the registry. | |
| tags: | | |
| type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }} | |
| type=raw,value=dev,enable=${{ github.ref == 'refs/heads/dev' }} | |
| type=sha,prefix=sha-,format=short | |
| - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| push: true | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: VERSION=${{ github.sha }} | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| deploy: | |
| runs-on: ubuntu-latest | |
| needs: publish | |
| if: github.ref == 'refs/heads/main' || github.ref == 'refs/heads/dev' | |
| # Each environment holds its own DEPLOY_UPDATE_WEBHOOK and | |
| # DEPLOY_UPDATE_TOKEN: main deploys itemize.no, dev deploys | |
| # dev.itemize.no. Both point at that host's watchtower HTTP API | |
| # (POST /v1/update behind Caddy), which restarts only the containers | |
| # whose image actually changed. | |
| environment: ${{ github.ref == 'refs/heads/main' && 'production' || 'development' }} | |
| steps: | |
| - name: Trigger redeploy | |
| env: | |
| URL: ${{ secrets.DEPLOY_UPDATE_WEBHOOK }} | |
| TOKEN: ${{ secrets.DEPLOY_UPDATE_TOKEN }} | |
| # -f so a failing webhook fails the job. The previous pipeline used | |
| # `curl -i`, which reported success even when the deploy never fired. | |
| run: | | |
| curl -fsS -X POST -H "Authorization: Bearer $TOKEN" "$URL" |