Ensure osquery instance healthcheck doesn't block on sending to resul… #4447
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: lint | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: '**' | |
| merge_group: | |
| types: [checks_requested] | |
| jobs: | |
| golangci: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [macos-latest, windows-latest, ubuntu-latest] | |
| name: lint | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version-file: './go.mod' | |
| check-latest: true | |
| cache: false | |
| - run: make deps | |
| - name: golangci-lint | |
| uses: golangci/golangci-lint-action@v9 | |
| with: | |
| skip-save-cache: true | |
| # Run again as a workaround for https://github.com/golangci/golangci-lint-action/issues/362 | |
| - name: golangci-lint | |
| if: ${{ always() }} | |
| run: golangci-lint run | |
| govulncheck: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [macos-latest, windows-latest, ubuntu-latest] | |
| name: govulncheck | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version-file: './go.mod' | |
| check-latest: true | |
| cache: false | |
| - name: Install govulncheck | |
| run: go install golang.org/x/vuln/cmd/govulncheck@latest | |
| shell: bash | |
| - id: govulncheck | |
| run: govulncheck -C . -format json ./... > govulncheck.json | |
| # If we need to exclude future go-tuf findings that do not apply to our version of go-tuf prior to v2, | |
| # adding a final select to JQ will do the trick: `select(. != "GO-2024-3166")` | |
| - name: Evaluate govulncheck results | |
| shell: bash | |
| run: | | |
| findingCount=$(jq -r '.finding | select ( . != null ) | .osv ' govulncheck.json | wc -l) | |
| findingCount=$((findingCount + 0)) | |
| if [[ $findingCount -ne 0 ]]; then | |
| printf "govulncheck reports %d findings" "$findingCount" | |
| jq -r '.finding | select ( . != null )' govulncheck.json | |
| exit 1 | |
| fi | |
| table_specs: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [macos-latest, windows-latest, ubuntu-latest] | |
| name: table specs | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version-file: './go.mod' | |
| check-latest: true | |
| cache: false | |
| - run: make deps | |
| - name: Build launcher | |
| run: go build -o ./build/launcher ./cmd/launcher | |
| - name: Check table specs | |
| run: ./build/launcher specs --required description --required name --quiet | |
| # This job is here as a github status check -- it allows us to move | |
| # the merge dependency from being on all the jobs to this single | |
| # one. | |
| lint_mergeable: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - run: true | |
| needs: | |
| - golangci | |
| - govulncheck | |
| - table_specs |