name: CI/CD on: push: branches: [ main, develop ] tags: - 'v*.*.*' pull_request: branches: [ main ] release: types: [ published ] env: GO_VERSION: '1.21' jobs: test: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v4 with: go-version: ${{ env.GO_VERSION }} - name: Cache Go modules uses: actions/cache@v3 with: path: ~/go/pkg/mod key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }} restore-keys: | ${{ runner.os }}-go- - name: Download dependencies run: go mod download - name: Verify dependencies run: go mod verify - name: Run tests run: go test -v -race -coverprofile=coverage.out ./... - name: Upload coverage to Codecov uses: codecov/codecov-action@v3 with: file: ./coverage.out flags: unittests name: codecov-umbrella - name: Build binary run: | CGO_ENABLED=0 go build -v -o passkey-auth . docker: runs-on: ubuntu-latest needs: test if: github.event_name == 'push' || github.event_name == 'release' || startsWith(github.ref, 'refs/tags/v') permissions: contents: read packages: write steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to GitHub Container Registry if: github.event_name == 'push' || github.event_name == 'release' || startsWith(github.ref, 'refs/tags/v') uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta uses: docker/metadata-action@v5 with: images: | ghcr.io/${{ github.repository }} tags: | type=ref,event=branch type=ref,event=pr type=semver,pattern={{version}} type=semver,pattern={{major}}.{{minor}} type=semver,pattern={{major}} type=sha,prefix={{branch}}-,enable=${{ github.ref_type == 'branch' }} type=sha,enable=${{ github.ref_type == 'tag' }} type=raw,value=latest,enable={{is_default_branch}} labels: | org.opencontainers.image.title=Passkey Auth org.opencontainers.image.description=WebAuthn/Passkey authentication server with admin approval workflow org.opencontainers.image.licenses=Apache-2.0 - name: Build and push Docker image uses: docker/build-push-action@v5 with: context: . platforms: linux/amd64,linux/arm64 push: ${{ github.event_name == 'push' || github.event_name == 'release' || startsWith(github.ref, 'refs/tags/v') }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max build-args: | BUILDKIT_INLINE_CACHE=1 GOCACHE=/root/.cache/go-build GOMODCACHE=/go/pkg/mod lint: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Go uses: actions/setup-go@v4 with: go-version: ${{ env.GO_VERSION }} - name: Run golangci-lint uses: golangci/golangci-lint-action@v3 with: version: latest args: --timeout=5m security: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Run Gosec Security Scanner uses: securego/gosec@master with: args: './...'