name: Tests on: push: branches: [main] pull_request: workflow_dispatch: permissions: contents: read jobs: secret-scan: name: Secret scan (gitleaks) runs-on: ubuntu-latest timeout-minutes: 10 steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Compute scan range (diff of new commits only) id: range run: | if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then RANGE="${{ github.event.pull_request.base.sha }}...${{ github.event.pull_request.head.sha }}" else BEFORE="${{ github.event.before }}" if [ "$BEFORE" = "0000000000000000000000000000000000000000" ]; then RANGE="$(git rev-list --max-parents=0 HEAD | tail -1)..$GITHUB_SHA" else RANGE="$BEFORE..$GITHUB_SHA" fi fi echo "RANGE=$RANGE" >> "$GITHUB_ENV" echo "Scanning range: $RANGE" # docker:// actions mount the workspace at /github/workspace — not the # host path from ${{ github.workspace }} (that path does not exist in-container). - name: Gitleaks (diff-only, fail on leak) uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} with: args: detect --source /github/workspace --log-opts="$GITLEAKS_RANGE" --redact --verbose test: name: Test (Go ${{ matrix.go }}) runs-on: ubuntu-latest strategy: fail-fast: false matrix: go: ["1.25", "stable"] steps: - uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v4 with: go-version: ${{ matrix.go }} cache: true - name: Verify dependencies run: | go mod verify go mod download - name: Check go mod tidy run: | go mod tidy git diff --exit-code go.mod go.sum - name: Vet run: go vet ./... - name: Build oo run: go build -trimpath -buildvcs=false -o /tmp/oo ./cmd/oo - name: Build office run: go build -trimpath -buildvcs=false -o /tmp/office ./cmd/office - name: Run tests run: go test -race -shuffle=on -count=1 ./...