Skip to content

ci: fix Go setup and consolidate Trivy scans - #277

Merged
appleboy merged 1 commit into
mainfrom
ci/fix-setup-go-and-trivy
Sep 28, 2026
Merged

appleboy merged 1 commit into
mainfrom
ci/fix-setup-go-and-trivy

Conversation

@appleboy

Copy link
Copy Markdown
Owner

Summary

Fix the lint job failing during Go setup: setup-go treats go.tools.mod as a plain version file and tries to install its entire contents as a version. Read the supported go.mod file instead, selecting Go 1.26.8.

Remove the duplicate filesystem scan workflow trivy.yml. Keep security.yml, including vulnerability, secret and misconfiguration checks, SARIF upload, the HIGH/CRITICAL failure gate, daily schedule and manual trigger. Update all three README variants to show one Trivy badge pointing to that workflow.

Related failure: https://github.com/appleboy/CodeGPT/actions/runs/36391694647/job/108828743375
Issue / Jira references: N/A; none supplied.

AI authorship

  • AI was used
  • Tool / model: OpenAI Codex (GPT-6)
  • AI-authored files: .github/workflows/testing.yml, .github/workflows/trivy.yml (deletion), README.md, README.zh-cn.md, README.zh-tw.md
  • Human line-by-line reviewed: None — not yet reviewed by a human.

Change classification

  • Leaf change: scoped CI configuration and documentation; no application behavior changes.
  • Plan / scope: repair Go setup, retain one source scan workflow and align README badges.

Verification

Setup: check out ci/fix-setup-go-and-trivy and run commands from the repository root with Go 1.26.8, make, Git and network access for Go dependencies. No services or credentials needed for local checks.

Check Expected result Status / observed result
make fmt Successful formatting Passed; no extra changes
make lint No lint issues Passed; 0 issues
go test ./... Existing tests pass Passed; 69 tests across 12 packages
git diff --check and git diff --staged --check No whitespace errors Passed
Exact setup-go parser from the failing action SHA Original input resolves to module contents; corrected input resolves to 1.26.8 Passed in local Node regression check
Workflow and README consistency check One filesystem workflow; badge image and target use existing workflow Passed across all three READMEs

Reviewer scenarios

  1. Inspect .github/workflows/testing.yml: the lint job must use go-version-file: go.mod. Inspect go.mod: the selected version is 1.26.8. Passed locally using the upstream parser. On the PR Actions page, confirm each lint job completes Setup go and reaches Run golangci-lint. Not run at preparation time; requires hosted CI after push.
  2. Run rg -l 'scan-type: "fs"' .github/workflows: expect only .github/workflows/security.yml. Inspect that workflow for vuln,secret,misconfig, SARIF upload and the HIGH/CRITICAL exit-code gate. Passed by local inspection and script.
  3. Run rg -n 'Trivy Security Scan|workflows/trivy.yml' README*.md: expect exactly one badge per README, each image and click target using security.yml, image query branch=main, and no deleted workflow references. Passed by local script. Badge status reflects main until merge.

Cleanup: N/A; verification creates no application data.

Security, risk and rollback

No secrets in the diff and no application permission or external interface changes. The retained scan preserves broader scanner coverage; Docker image scanning is unchanged. Main risk is CI configuration behavior on hosted runners. Revert this commit to restore the previous configuration.

Reviewer guide: one reviewer; inspect workflow version selection and retained scan coverage, then spot-check README links.

- Read the supported module file for the Go version
- Remove the duplicate source security scan
- Align all README security badges with the retained workflow
Copilot AI lite review requested due to automatic review settings September 28, 2026 07:31

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@appleboy
appleboy merged commit 85e39d8 into main Sep 28, 2026
20 of 21 checks passed
@appleboy
appleboy deleted the ci/fix-setup-go-and-trivy branch September 28, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants