name: CI # The release workflow gates a tag, which is late: a broken commit sits green until # somebody decides to publish. This runs the same checks on the way in. # # push is scoped to main so that a branch pushed as part of a pull request is not checked # twice. # # No actions/checkout, deliberately -- same as the terdut-server, letsvisit and charts # workflows. The runner image is ubuntu:22.04 whose `nodejs` package is Node 12, and # actions/checkout@v4 is built with ES2022 static initialiser blocks, so it dies with # `SyntaxError: Unexpected token '{'` before running. Cloning with git directly avoids JS # actions entirely. This repo is public, so the clone needs no credential at all. # # `${{ }}` values are passed through `env:` and referenced as quoted shell variables: a # ref name is attacker-influenced by anyone who can push a branch or open a PR, and # expanding one straight into `run:` is a shell-injection vector. on: push: branches: [main] pull_request: # A rapid series of pushes only needs the last one checked. concurrency: group: ci-${{ github.ref }} cancel-in-progress: true env: REPO_URL: https://git.ryuvia.com/niklas/terdut-tui.git jobs: test: runs-on: ubuntu-latest container: image: golang:1.26.6-bookworm # act_runner destroys a job's own volumes when it finishes, so without these every # run re-downloads the whole module graph. The names must appear in the runner's # container.valid_volumes allowlist (charts/act-runner in the k8s repo); unlisted # volumes are dropped silently, so a workflow that looks correct can still be # running uncached. volumes: - go-mod-cache:/go/pkg/mod - go-build-cache:/root/.cache/go-build - gobin-cache:/go/bin steps: - name: Checkout env: REF_NAME: ${{ github.ref_name }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} run: | if [ -n "$HEAD_SHA" ]; then # A pull_request ref_name is "/merge", which is not a fetchable branch. git clone "$REPO_URL" . git checkout -q "$HEAD_SHA" else git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" . fi - name: Vet run: go vet ./... # Covers the API client against a stub server, the Update state machine, and View # rendering -- all three are pure enough to test without a terminal. - name: Test run: go test ./...