name: CI on: # PR branches only, as in the org's other repos. push: branches-ignore: [master] workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ !startsWith(github.ref_name, 'release-please--') }} permissions: contents: read jobs: test: uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1 with: # "1.26", not go.mod: `go 1.26.0` there would pin that exact patch. go-version: "1.26" # Never run here before; enable once its findings are triaged. run-golangci-lint: false build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 with: persist-credentials: false - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: Build image uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: Dockerfile push: false zizmor: uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 # The one name the ruleset requires, however the jobs above change. required-checks-passed: name: Required checks passed runs-on: ubuntu-latest needs: [test, build, zizmor] if: always() steps: - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') run: exit 1