Add THIRD_PARTY_NOTICES.md and a generator for it #267
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Copyright 2024 NVIDIA CORPORATION | |
| # | |
| # Licensed under the Apache License, Version 2.0 (the "License"); | |
| # you may not use this file except in compliance with the License. | |
| # You may obtain a copy of the License at | |
| # | |
| # http://www.apache.org/licenses/LICENSE-2.0 | |
| # | |
| # Unless required by applicable law or agreed to in writing, software | |
| # distributed under the License is distributed on an "AS IS" BASIS, | |
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | |
| # See the License for the specific language governing permissions and | |
| # limitations under the License. | |
| name: Golang | |
| on: | |
| pull_request: | |
| branches: | |
| - main | |
| - release-* | |
| push: | |
| branches: | |
| - main | |
| - release-* | |
| jobs: | |
| check: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| name: Checkout code | |
| - name: Get Golang version | |
| id: vars | |
| run: | | |
| GOLANG_VERSION=$( grep "GOLANG_VERSION ?=" versions.mk ) | |
| echo "GOLANG_VERSION=${GOLANG_VERSION##GOLANG_VERSION ?= }" >> $GITHUB_ENV | |
| - name: Install Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GOLANG_VERSION }} | |
| - name: Lint | |
| uses: golangci/golangci-lint-action@v9 | |
| with: | |
| version: latest | |
| args: -v --timeout 5m | |
| skip-cache: true | |
| - name: Check golang modules | |
| run: make check-vendor | |
| test: | |
| name: Unit test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v7 | |
| - name: Get Golang version | |
| id: vars | |
| run: | | |
| GOLANG_VERSION=$( grep "GOLANG_VERSION ?=" versions.mk ) | |
| echo "GOLANG_VERSION=${GOLANG_VERSION##GOLANG_VERSION ?= }" >> $GITHUB_ENV | |
| - name: Install Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GOLANG_VERSION }} | |
| - run: make test | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| name: Checkout code | |
| - name: Get Golang version | |
| id: vars | |
| run: | | |
| GOLANG_VERSION=$( grep "GOLANG_VERSION ?=" versions.mk ) | |
| echo "GOLANG_VERSION=${GOLANG_VERSION##GOLANG_VERSION ?= }" >> $GITHUB_ENV | |
| - name: Install Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GOLANG_VERSION }} | |
| - run: make build | |
| # Regenerates THIRD_PARTY_NOTICES.md and fails if it differs from the | |
| # committed copy, so a dependency change cannot land without refreshed | |
| # attribution. | |
| # | |
| # This runs on every build rather than behind a changed-paths filter. The | |
| # inventory is the import closure of ./..., so it changes when ordinary .go | |
| # files change their imports, not only when go.mod or vendor/ move — and it | |
| # also covers the bundled non-Go files declared in hack/notices. A filter | |
| # keyed on dependency manifests would pass green while the committed file | |
| # went stale, and the failure would surface on main instead of on the pull | |
| # request that caused it. | |
| notices: | |
| name: Check third-party notices | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| name: Checkout code | |
| - name: Get Golang version | |
| id: vars | |
| run: | | |
| GOLANG_VERSION=$( grep "GOLANG_VERSION ?=" versions.mk ) | |
| echo "GOLANG_VERSION=${GOLANG_VERSION##GOLANG_VERSION ?= }" >> $GITHUB_ENV | |
| - name: Install Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GOLANG_VERSION }} | |
| - run: make notices-check |