From 5b5dfbf03409159ef5fda8efec1236200ee27ecb Mon Sep 17 00:00:00 2001 From: Imani Manyara Date: Tue, 29 Sep 2026 04:44:24 -0400 Subject: [PATCH] Run CI on pull requests only, point Dependabot at src/, float first-party actions CI and CodeQL also ran on push to main, which runs after a change has landed and doubles every merge; pull_request, workflow_dispatch and CodeQL's weekly schedule remain. Dependabot's gomod entry looked for go.mod at the root while the module lives in src/, so every Go update job failed. First-party actions (actions/*, github/*) now float on their major tag and third-party ones stay SHA-pinned, per the org convention. golangci-lint moves to its latest release, v2.14.0. --- .github/dependabot.yml | 4 +++- .github/workflows/ci.yml | 12 +++++------- .github/workflows/codeql.yml | 10 ++++------ .github/workflows/release.yml | 6 +++--- 4 files changed, 15 insertions(+), 17 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 52454a5..cb1e952 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,7 +1,9 @@ version: 2 updates: - package-ecosystem: "gomod" - directory: "/" + # The module lives in src/, not at the root; "/" finds no go.mod and the + # update job fails. + directory: "/src" schedule: interval: "weekly" day: "monday" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9de05e2..9486514 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -8,8 +8,6 @@ on: # re-run a green commit after changing a secret or a runner image, without # pushing an empty commit to do it. workflow_dispatch: - push: - branches: [main] pull_request: branches: [main] @@ -33,10 +31,10 @@ jobs: matrix: os: [ubuntu-latest, macos-latest, windows-latest] steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + - uses: actions/setup-go@v7 with: # The module declares its toolchain; `stable` moved to 1.27 under a # golangci-lint built with 1.26, which panics on the newer stdlib. @@ -51,7 +49,7 @@ jobs: - name: Lint uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: - version: v2.12.2 + version: v2.14.0 # The module is src/, and the action runs where it is told to. Without # this it lints a directory with no Go in it and passes. working-directory: src @@ -92,7 +90,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: fetch-depth: 0 persist-credentials: false @@ -113,7 +111,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: persist-credentials: false - name: shellcheck diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c2173fa..2eb0653 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -2,8 +2,6 @@ name: CodeQL on: workflow_dispatch: - push: - branches: [main] pull_request: branches: [main] schedule: @@ -34,12 +32,12 @@ jobs: # was aimed at is gone, and the Go that replaced it was never analysed. language: [go, actions] steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: persist-credentials: false # Pin the toolchain from go.mod. CodeQL's autobuild otherwise uses whatever # Go the runner image ships, which need not satisfy the module's directive. - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + - uses: actions/setup-go@v7 if: matrix.language == 'go' with: go-version-file: src/go.mod @@ -50,7 +48,7 @@ jobs: # worse on a different day, reports a clean result for a codebase it # never read. cache: false - - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + - uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # Go must be built for CodeQL to read it - the extractor works from a @@ -71,4 +69,4 @@ jobs: # rejects the other's: "Go does not support the none build mode" and # "GitHub Actions does not support the autobuild build mode". build-mode: ${{ matrix.language == 'go' && 'autobuild' || 'none' }} - - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + - uses: github/codeql-action/analyze@v4 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5bed73d..143cacb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -44,11 +44,11 @@ jobs: id-token: write # keyless signing for the provenance attestation attestations: write # write the build-provenance attestation steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: fetch-depth: 0 # full history + tags for GoReleaser - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 + - uses: actions/setup-go@v7 with: go-version-file: src/go.mod cache: true @@ -103,6 +103,6 @@ jobs: # checksums file lists them all, so `gh attestation verify # --repo /` works for any downloaded binary or archive. - name: Attest build provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4 with: subject-checksums: build/dist/checksums.txt