Clear OSV-Scanner findings: bump go directive to 1.25.0 + remaining deps #901
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Go | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| id-token: write | |
| jobs: | |
| lint: | |
| name: Lint | |
| runs-on: | |
| group: databricks-protected-runner-group | |
| labels: linux-ubuntu-latest | |
| steps: | |
| - name: Check out code into the Go module directory | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup JFrog | |
| uses: ./.github/actions/setup-jfrog | |
| - name: Set up Go Toolchain | |
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 | |
| with: | |
| go-version: '1.25.x' | |
| cache: false | |
| - name: Lint | |
| uses: golangci/golangci-lint-action@db582008a42febd596419635a5abc9d9815daa9c # v9.2.1 | |
| with: | |
| # v2.x is built with go 1.25+, which is required so the | |
| # linter can read Go 1.25 stdlib export data. The v1 family | |
| # was built with go ≤1.23 and produces "could not import | |
| # sync/atomic" typecheck errors against our `go 1.25.0` | |
| # directive. | |
| version: 'v2.12.2' | |
| build-and-test: | |
| name: Test and Build | |
| strategy: | |
| # Matches Go's release support window. Per go.dev/doc/devel/release, | |
| # only the latest two major releases receive security patches. | |
| # As of 2026-05 that's 1.25 (Active LTS) and 1.26. The protected | |
| # runners pin GOTOOLCHAIN=local so we can't include 1.24 — Go would | |
| # refuse to satisfy the `go 1.25.0` directive without auto-downloading. | |
| matrix: | |
| go-version: ['1.25.x', '1.26.x'] | |
| runs-on: | |
| group: databricks-protected-runner-group | |
| labels: linux-ubuntu-latest | |
| steps: | |
| - name: Check out code into the Go module directory | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup JFrog | |
| uses: ./.github/actions/setup-jfrog | |
| - name: Set up Go Toolchain | |
| uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 | |
| with: | |
| go-version: ${{ matrix.go-version }} | |
| cache: false | |
| - name: Cache Go artifacts | |
| uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: | | |
| ~/go/pkg/mod | |
| ~/.cache/go-build | |
| key: ${{ runner.os }}-go-${{ matrix.go-version }}-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-${{ matrix.go-version }}- | |
| - name: Get dependencies | |
| run: | | |
| if ! command -v make &> /dev/null ; then | |
| echo "Installing make" | |
| apt-get update | |
| apt-get install -y make | |
| fi | |
| if ! command -v git &> /dev/null ; then | |
| echo "Installing git" | |
| apt-get update | |
| apt-get install -y git | |
| fi | |
| go get -v -t -d ./... | |
| - name: Test | |
| run: make test | |
| env: | |
| CGO_ENABLED: 0 | |
| - name: Test-Race | |
| run: make test-race | |
| - name: Build | |
| run: make linux |