Skip to content

Fix device_data unmarshal and fatal exit code (#11) #51

Fix device_data unmarshal and fatal exit code (#11)

Fix device_data unmarshal and fatal exit code (#11) #51

Workflow file for this run

name: CI Pipeline
on:
push:
branches:
- master
pull_request:
branches:
- master
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
lint:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
- name: Run linter
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.12.2
- name: Scan for secrets
# gitleaks/gitleaks-action requires a paid license for GitHub
# organizations. Run the underlying OSS (MIT) gitleaks CLI directly
# via its official image instead, which needs no license.
uses: docker://ghcr.io/gitleaks/gitleaks:v8.30.1
with:
args: detect --source=. --no-git --verbose --redact
test:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
- name: Run tests
run: go test -race -covermode=atomic -coverprofile=coverage.out ./...
- name: Enforce coverage floor
# Total statement coverage from the merged profile must stay at or
# above 80% (see AGENTS.md). The number comes from the "total:" line
# of go tool cover -func.
run: |
total=$(go tool cover -func=coverage.out | awk '/^total:/ {sub(/%/, "", $NF); print $NF}')
echo "Total statement coverage: ${total}%"
if ! awk -v t="$total" 'BEGIN { exit !(t >= 80.0) }'; then
echo "::error::Coverage ${total}% is below the 80% floor"
exit 1
fi
docker:
needs: [ lint, test ]
# Push events only: fork pull requests must never run on the self-hosted
# runner, where they could execute arbitrary Dockerfile code and poison
# the persistent buildx builder cache.
if: github.event_name == 'push'
runs-on: [ self-hosted ]
# The named buildx builder is shared daemon state; concurrent docker jobs
# (master push + tag push) race on it. Serialize them repo-wide.
concurrency:
group: docker-builder
permissions:
contents: read
packages: write
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Docker meta
id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: |
yottabyte/meterlogger
ghcr.io/${{ github.repository }}
tags: |
type=sha,format=long
- name: Remove stale buildx builder
# A leftover instance from a previous run makes setup-buildx fail with
# "existing instance but no append mode". Remove it but keep the state
# volume so the go mod / go-build cache mounts survive.
run: docker buildx rm --keep-state meterlogger-builder || true
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
with:
# Stable builder name so the BuildKit instance (and its cache
# mounts for go mod / go-build) persists across runs on this
# self-hosted runner.
name: meterlogger-builder
- name: Login to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_ACCESSTOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
push: true
platforms: linux/amd64,linux/arm64
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: GIT_SHA=${{ github.sha }}
# Supply chain attestations: SBOM + max-mode provenance, attached
# to the image manifest so Docker Hub can show the build origin
# and dependency inventory.
provenance: mode=max
sbom: true