Repository navigation
ci: fix Go setup and consolidate Trivy scans - #277
Merged
Merged
Conversation
- Read the supported module file for the Go version - Remove the duplicate source security scan - Align all README security badges with the retained workflow
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix the lint job failing during Go setup: setup-go treats
go.tools.modas a plain version file and tries to install its entire contents as a version. Read the supportedgo.modfile instead, selecting Go 1.26.8.Remove the duplicate filesystem scan workflow
trivy.yml. Keepsecurity.yml, including vulnerability, secret and misconfiguration checks, SARIF upload, the HIGH/CRITICAL failure gate, daily schedule and manual trigger. Update all three README variants to show one Trivy badge pointing to that workflow.Related failure: https://github.com/appleboy/CodeGPT/actions/runs/36391694647/job/108828743375
Issue / Jira references: N/A; none supplied.
AI authorship
.github/workflows/testing.yml,.github/workflows/trivy.yml(deletion),README.md,README.zh-cn.md,README.zh-tw.mdChange classification
Verification
Setup: check out
ci/fix-setup-go-and-trivyand run commands from the repository root with Go 1.26.8, make, Git and network access for Go dependencies. No services or credentials needed for local checks.make fmtmake lintgo test ./...git diff --checkandgit diff --staged --checkReviewer scenarios
.github/workflows/testing.yml: the lint job must usego-version-file: go.mod. Inspectgo.mod: the selected version is 1.26.8. Passed locally using the upstream parser. On the PR Actions page, confirm each lint job completes Setup go and reaches Run golangci-lint. Not run at preparation time; requires hosted CI after push.rg -l 'scan-type: "fs"' .github/workflows: expect only.github/workflows/security.yml. Inspect that workflow forvuln,secret,misconfig, SARIF upload and the HIGH/CRITICAL exit-code gate. Passed by local inspection and script.rg -n 'Trivy Security Scan|workflows/trivy.yml' README*.md: expect exactly one badge per README, each image and click target usingsecurity.yml, image querybranch=main, and no deleted workflow references. Passed by local script. Badge status reflects main until merge.Cleanup: N/A; verification creates no application data.
Security, risk and rollback
No secrets in the diff and no application permission or external interface changes. The retained scan preserves broader scanner coverage; Docker image scanning is unchanged. Main risk is CI configuration behavior on hosted runners. Revert this commit to restore the previous configuration.
Reviewer guide: one reviewer; inspect workflow version selection and retained scan coverage, then spot-check README links.