ci: sync with netresearch/.github templates/go-app - #556
Conversation
Auto-generated by scripts/sync-template.sh. Any changes you want to keep must be declared in .github/template.yaml's intentional-drift: list — the check-template-drift.yml job will otherwise revert them on next sync. Signed-off-by: Sebastian Mendel <info@sebastianmendel.de>
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned Files
|
There was a problem hiding this comment.
Automated approval for maintainer PR
All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.
There was a problem hiding this comment.
Pull request overview
Syncs this repository’s GitHub Actions workflows back to the canonical netresearch/.github go-app template, aligning CI/security automation with upstream defaults.
Changes:
- Extend the container build workflow job permissions to include
security-events: write. - Simplify CodeQL workflow by removing custom language detection and delegating language selection to the reusable workflow via
languages: auto.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| .github/workflows/container.yml | Adds security-events: write permission to the container job (template alignment / security reporting support). |
| .github/workflows/codeql.yml | Removes in-repo language detection job; uses template workflow with languages: auto. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #556 +/- ##
=======================================
Coverage 83.91% 83.91%
=======================================
Files 17 17
Lines 1716 1716
=======================================
Hits 1440 1440
Misses 218 218
Partials 58 58
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
…rm64 only Template default is 5 platforms (386/amd64/arm-v6/arm-v7/arm64) but oven/bun and golang-alpine used in this repo's Dockerfile only publish amd64+arm64 variants. Buildx fails with 'no match for platform in manifest' on the other three. Narrow to linux/amd64,linux/arm64 and record container.yml as intentional-drift. Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
There was a problem hiding this comment.
Automated approval for maintainer PR
All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.
Auto-opened by sync-template.sh. Brings this repo back into alignment with the canonical
go-apptemplate innetresearch/.github.To keep any diverging files, add their paths to
.github/template.yaml'sintentional-drift:list before merging — otherwise the next sync run will revert them.