Clear OSV-Scanner findings: bump go directive to 1.25.0 + remaining deps #897
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Go | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| id-token: write | |
| jobs: | |
| lint: | |
| name: Lint | |
| runs-on: | |
| group: databricks-protected-runner-group | |
| labels: linux-ubuntu-latest | |
| steps: | |
| - name: Check out code into the Go module directory | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup JFrog | |
| uses: ./.github/actions/setup-jfrog | |
| - name: Set up Go Toolchain | |
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 | |
| with: | |
| go-version: '1.25.x' | |
| cache: false | |
| - name: Lint | |
| uses: golangci/golangci-lint-action@d6238b002a20823d52840fda27e2d4891c5952dc # v4 | |
| with: | |
| # v1.x family is the last to use the legacy config schema. | |
| # v1.61 was built with go 1.23; the `run.go: '1.23'` in | |
| # .golangci.yml tells it to treat our code as Go 1.23 | |
| # despite the go 1.25.0 directive in go.mod. Migrating to | |
| # v2 + the v2 config format is a separate cleanup. | |
| version: 'v1.61' | |
| build-and-test: | |
| name: Test and Build | |
| strategy: | |
| # Matches Go's release support window. Per go.dev/doc/devel/release, | |
| # only the latest two major releases receive security patches. | |
| # As of 2026-05 that's 1.25 (Active LTS) and 1.26. The protected | |
| # runners pin GOTOOLCHAIN=local so we can't include 1.24 — Go would | |
| # refuse to satisfy the `go 1.25.0` directive without auto-downloading. | |
| matrix: | |
| go-version: ['1.25.x', '1.26.x'] | |
| runs-on: | |
| group: databricks-protected-runner-group | |
| labels: linux-ubuntu-latest | |
| steps: | |
| - name: Check out code into the Go module directory | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup JFrog | |
| uses: ./.github/actions/setup-jfrog | |
| - name: Set up Go Toolchain | |
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 | |
| with: | |
| go-version: ${{ matrix.go-version }} | |
| cache: false | |
| - name: Cache Go artifacts | |
| uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: | | |
| ~/go/pkg/mod | |
| ~/.cache/go-build | |
| key: ${{ runner.os }}-go-${{ matrix.go-version }}-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-${{ matrix.go-version }}- | |
| - name: Get dependencies | |
| run: | | |
| if ! command -v make &> /dev/null ; then | |
| echo "Installing make" | |
| apt-get update | |
| apt-get install -y make | |
| fi | |
| if ! command -v git &> /dev/null ; then | |
| echo "Installing git" | |
| apt-get update | |
| apt-get install -y git | |
| fi | |
| go get -v -t -d ./... | |
| - name: Test | |
| run: make test | |
| env: | |
| CGO_ENABLED: 0 | |
| - name: Test-Race | |
| run: make test-race | |
| - name: Build | |
| run: make linux |