Fix device_data unmarshal and fatal exit code (#11) #51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI Pipeline | |
| on: | |
| push: | |
| branches: | |
| - master | |
| pull_request: | |
| branches: | |
| - master | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| - name: Run linter | |
| uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 | |
| with: | |
| version: v2.12.2 | |
| - name: Scan for secrets | |
| # gitleaks/gitleaks-action requires a paid license for GitHub | |
| # organizations. Run the underlying OSS (MIT) gitleaks CLI directly | |
| # via its official image instead, which needs no license. | |
| uses: docker://ghcr.io/gitleaks/gitleaks:v8.30.1 | |
| with: | |
| args: detect --source=. --no-git --verbose --redact | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| - name: Run tests | |
| run: go test -race -covermode=atomic -coverprofile=coverage.out ./... | |
| - name: Enforce coverage floor | |
| # Total statement coverage from the merged profile must stay at or | |
| # above 80% (see AGENTS.md). The number comes from the "total:" line | |
| # of go tool cover -func. | |
| run: | | |
| total=$(go tool cover -func=coverage.out | awk '/^total:/ {sub(/%/, "", $NF); print $NF}') | |
| echo "Total statement coverage: ${total}%" | |
| if ! awk -v t="$total" 'BEGIN { exit !(t >= 80.0) }'; then | |
| echo "::error::Coverage ${total}% is below the 80% floor" | |
| exit 1 | |
| fi | |
| docker: | |
| needs: [ lint, test ] | |
| # Push events only: fork pull requests must never run on the self-hosted | |
| # runner, where they could execute arbitrary Dockerfile code and poison | |
| # the persistent buildx builder cache. | |
| if: github.event_name == 'push' | |
| runs-on: [ self-hosted ] | |
| # The named buildx builder is shared daemon state; concurrent docker jobs | |
| # (master push + tag push) race on it. Serialize them repo-wide. | |
| concurrency: | |
| group: docker-builder | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Docker meta | |
| id: meta | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 | |
| with: | |
| images: | | |
| yottabyte/meterlogger | |
| ghcr.io/${{ github.repository }} | |
| tags: | | |
| type=sha,format=long | |
| - name: Remove stale buildx builder | |
| # A leftover instance from a previous run makes setup-buildx fail with | |
| # "existing instance but no append mode". Remove it but keep the state | |
| # volume so the go mod / go-build cache mounts survive. | |
| run: docker buildx rm --keep-state meterlogger-builder || true | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| with: | |
| # Stable builder name so the BuildKit instance (and its cache | |
| # mounts for go mod / go-build) persists across runs on this | |
| # self-hosted runner. | |
| name: meterlogger-builder | |
| - name: Login to Docker Hub | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_ACCESSTOKEN }} | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| push: true | |
| platforms: linux/amd64,linux/arm64 | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: GIT_SHA=${{ github.sha }} | |
| # Supply chain attestations: SBOM + max-mode provenance, attached | |
| # to the image manifest so Docker Hub can show the build origin | |
| # and dependency inventory. | |
| provenance: mode=max | |
| sbom: true |