name: CI on: push: branches: [master, develop] pull_request: branches: [master] env: GO_VERSION: "1.21" jobs: lint: name: Lint runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v5 with: go-version: ${{ env.GO_VERSION }} cache: true - name: golangci-lint uses: golangci/golangci-lint-action@v3 with: version: v1.55.2 args: --timeout=5m test: name: Test runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v5 with: go-version: ${{ env.GO_VERSION }} cache: true - name: Run tests run: go test -v -race -coverprofile=coverage.out -covermode=atomic ./... - name: Upload coverage uses: codecov/codecov-action@v3 with: file: ./coverage.out fail_ci_if_error: false build: name: Build runs-on: ubuntu-latest needs: [lint, test] steps: - uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v5 with: go-version: ${{ env.GO_VERSION }} cache: true - name: Build agent-server run: go build -ldflags="-s -w" -o bin/agent-server ./cmd/agent-server docker: name: Docker Build runs-on: ubuntu-latest needs: [build] if: github.event_name == 'push' && github.ref == 'refs/heads/main' steps: - uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Login to GitHub Container Registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and push agent-server uses: docker/build-push-action@v5 with: context: . file: deployments/docker/Dockerfile.agent push: true tags: | ghcr.io/${{ github.repository }}/agent-server:latest ghcr.io/${{ github.repository }}/agent-server:${{ github.sha }} cache-from: type=gha cache-to: type=gha,mode=max security-scan: name: Security Scan runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: scan-type: "fs" scan-ref: "." ignore-unfixed: true format: "sarif" output: "trivy-results.sarif" - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v2 if: always() with: sarif_file: "trivy-results.sarif"