Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 35 additions & 13 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ name: ci

on:
push:
branches:
- main
pull_request:

permissions:
Expand All @@ -11,10 +13,10 @@ jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
Expand All @@ -25,54 +27,74 @@ jobs:
- name: Install golangci-lint
run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.13.2
- name: Lint
run: make lint
run: make lint-check GOLANGCI_LINT=golangci-lint
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "26.8.2"
- name: Documentation metadata
run: |
node --test scripts/llms-metadata.test.mjs
node scripts/generate-llms.mjs
git diff --exit-code -- docs/llms.txt
windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.27.1"
cache: true
- name: Test latest Go on Windows
run: go test -race ./...
audit:
# The release contract exercises pinned macOS signing/verifier tools with
# test doubles; run the whole audit on the platform whose system paths and
# BSD tool semantics those boundaries deliberately freeze.
runs-on: macos-15
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Install dependencies
run: go mod download
- name: Race tests on macOS
run: go test -race ./...
- name: Install pinned ShellCheck
run: |
shellcheck_bin="$(./scripts/bootstrap-shellcheck.sh "$RUNNER_TEMP/shellcheck")"
printf '%s\n' "${shellcheck_bin%/*}" >> "$GITHUB_PATH"
- name: Lint workflows
run: go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12
- name: Staticcheck
run: go run honnef.co/go/tools/cmd/staticcheck@v0.8.1 ./...
- name: Deadcode
run: |
output_file=$(mktemp)
go run golang.org/x/tools/cmd/deadcode@v0.49.0 -test ./... > "$output_file"
go run golang.org/x/tools/cmd/deadcode@v0.50.0 -test ./... > "$output_file"
if [ -s "$output_file" ]; then
cat "$output_file"
exit 1
fi
- name: Security scan
run: go run github.com/securego/gosec/v2/cmd/gosec@v2.29.0 ./...
- name: Install vulnerability scanner
run: go install golang.org/x/vuln/cmd/govulncheck@v1.7.0
run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0
- name: Source vulnerability scan
run: '"$(go env GOPATH)/bin/govulncheck" -db=https://vuln.go.dev -test ./...'
- uses: goreleaser/goreleaser-action@v7
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.17.1
version: v2.18.1
args: check --config .goreleaser.yml
- name: Build credential-free snapshot
uses: goreleaser/goreleaser-action@v7
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.17.1
version: v2.18.1
args: release --snapshot --clean --skip=publish --config .goreleaser.yml
- name: Snapshot binary vulnerability scan
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/crabbox-hydrate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,12 +35,12 @@ jobs:
runs-on: [self-hosted, crabbox, openclaw, goplaces, "${{ inputs.crabbox_runner_label }}"]
timeout-minutes: 120
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.ref || github.ref }}
persist-credentials: false

- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,15 +25,15 @@ jobs:
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/configure-pages@v6
- uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
with:
enablement: true
- uses: actions/upload-pages-artifact@v5
- uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: docs
include-hidden-files: true
- id: deployment
uses: actions/deploy-pages@v5
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
4 changes: 2 additions & 2 deletions .github/workflows/release-assets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -187,12 +187,12 @@ jobs:
run: |
set -euo pipefail
[[ -x "$GO_BIN" ]]
[[ "$(GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off "$GO_BIN" env GOVERSION)" == go1.26.7 ]]
[[ "$(GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off "$GO_BIN" env GOVERSION)" == go1.26.8 ]]
(cd "$SOURCE" && /usr/bin/env GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off \
GOFLAGS=-mod=readonly GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org \
GOVCS='*:off' "$GO_BIN" mod download all)
/usr/bin/env GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off \
GOBIN="$RUNNER_TEMP/tools" "$GO_BIN" install golang.org/x/vuln/cmd/govulncheck@v1.7.0
GOBIN="$RUNNER_TEMP/tools" "$GO_BIN" install golang.org/x/vuln/cmd/govulncheck@v1.8.0
[[ -x "$RUNNER_TEMP/tools/govulncheck" ]]
(cd "$SOURCE" && /usr/bin/env -u GH_TOKEN -u GITHUB_TOKEN \
GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off GOFLAGS=-mod=readonly \
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,11 @@ jobs:
# exercise macOS-only producer and verifier boundaries.
runs-on: macos-15
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
Expand Down Expand Up @@ -49,14 +49,14 @@ jobs:
./scripts/test-release-local.sh
./scripts/test-security-ci.sh
- name: Install vulnerability scanner
run: go install golang.org/x/vuln/cmd/govulncheck@v1.7.0
run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0
- name: Source vulnerability scan
run: '"$(go env GOPATH)/bin/govulncheck" -db=https://vuln.go.dev -test ./...'
- name: Build credential-free snapshot
uses: goreleaser/goreleaser-action@v7
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.17.1
version: v2.18.1
args: release --snapshot --clean --skip=publish --config .goreleaser.yml
- name: Snapshot binary vulnerability scan
env:
Expand Down
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@

## Unreleased

- Build: require Go 1.26.8 for upstream compiler and runtime fixes; update GoReleaser to 2.18.1, Node to 26.8.2, deadcode to 0.50.0, and govulncheck to 1.8.0 with matching release-verifier pins.
- CI: pin Actions by commit, test Windows with Go 1.27.1 and macOS with the race detector, verify documentation metadata, reject formatting drift, and avoid duplicate branch-push audits.

- CI: update the reviewed GitHub CLI pin to 2.100.0 so release contract tests accept the current Homebrew version installed by CI.
- Build: update Kong to 1.16.1, golangci-lint to 2.13.2, deadcode to 0.49.0, gosec to 2.29.0, govulncheck to 1.7.0, and setup-go to v7.

Expand Down
6 changes: 5 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
.PHONY: lint test coverage
.PHONY: lint lint-check test coverage
.PHONY: e2e goplaces force

GOLANGCI_LINT_VERSION ?= v2.13.2
Expand All @@ -8,6 +8,10 @@ lint:
$(GOLANGCI_LINT) fmt
$(GOLANGCI_LINT) run ./...

lint-check:
$(GOLANGCI_LINT) fmt --diff
$(GOLANGCI_LINT) run ./...

test:
go test ./...

Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

[![CI](https://img.shields.io/github/actions/workflow/status/openclaw/goplaces/ci.yml?branch=main&style=flat-square&label=ci)](https://github.com/openclaw/goplaces/actions/workflows/ci.yml)
[![GitHub release](https://img.shields.io/github/v/release/openclaw/goplaces?style=flat-square)](https://github.com/openclaw/goplaces/releases/latest)
[![Go](https://img.shields.io/badge/Go-1.26.7-00ADD8?style=flat-square&logo=go&logoColor=white)](https://go.dev/dl/)
[![Go](https://img.shields.io/badge/Go-1.26.8-00ADD8?style=flat-square&logo=go&logoColor=white)](https://go.dev/dl/)
[![License](https://img.shields.io/github/license/openclaw/goplaces?style=flat-square)](LICENSE)
[![Homebrew](https://img.shields.io/badge/Homebrew-openclaw%2Ftap-FBB040?style=flat-square&logo=homebrew&logoColor=black)](https://github.com/openclaw/homebrew-tap/blob/main/Casks/goplaces.rb)
[![Docs](https://img.shields.io/badge/docs-goplaces.sh-3b82f6?style=flat-square)](https://goplaces.sh)
Expand All @@ -19,7 +19,7 @@ Homebrew installs the published binary on macOS or Linux:
brew install --cask openclaw/tap/goplaces
```

With Go 1.26.7 or newer:
With Go 1.26.8 or newer:

```sh
go install github.com/steipete/goplaces/cmd/goplaces@latest
Expand Down Expand Up @@ -99,7 +99,7 @@ See the [Go package reference](https://pkg.go.dev/github.com/steipete/goplaces)

## Development

Go 1.26.7 is required.
Go 1.26.8 is required.

```sh
go mod download
Expand Down
2 changes: 2 additions & 0 deletions docs/development.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,8 @@ make lint test coverage

The coverage target enforces the repository's coverage threshold. The CI workflow also runs workflow linting, static analysis, security scanners, release configuration checks, and credential-free release builds.

Use `make lint-check` to check formatting without modifying files. CI tests the declared Go floor on Linux and macOS, runs race tests on macOS and on Windows with the latest stable Go, and verifies the Node documentation metadata tests and generated index. Staticcheck runs through golangci-lint.

## Authenticated end-to-end tests

End-to-end tests are optional because they call Google services and incur normal quota or billing usage.
Expand Down
2 changes: 1 addition & 1 deletion docs/releasing.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ Run the full local proof set before requesting either serialized gate:
- formatting and clean-diff checks;
- autoreview to no accepted or actionable findings.

Run `scripts/release-local --check` for the aggregated preflight. It must reject ambient Go build controls, the wrong native Go version, a dirty or stale checkout, a non-default branch, and any mismatch with current protected `main`. The check builds pinned govulncheck v1.7.0 with the pinned Go 1.26.7 producer into its private audit directory, verifies the reviewed module checksum, then disables Go module resolution while querying the exact official vulnerability database URL. It never trusts a user-level `go/bin` lookup.
Run `scripts/release-local --check` for the aggregated preflight. It must reject ambient Go build controls, the wrong native Go version, a dirty or stale checkout, a non-default branch, and any mismatch with current protected `main`. The check builds pinned govulncheck v1.8.0 with the pinned Go 1.26.8 producer into its private audit directory, verifies the reviewed module checksum, then disables Go module resolution while querying the exact official vulnerability database URL. It never trusts a user-level `go/bin` lookup.

For a gated pilot or draft, copy `.mac-release.env.example` to the ignored `.mac-release.env`, keep mode `0400` or `0600`, and set the two direct runtime locators shown there: `MAC_RELEASE_CODESIGN_KEYCHAIN` and exported `NOTARYTOOL_KEYCHAIN_PROFILE`. The file is strictly parsed and frozen before `release-mac-app` reads it. Package-secret and 1Password lookup fields are rejected in this lane so the helper and producer can execute with pinned, system-only tool paths. `scripts/release-local` also pins the reviewed SHA-256 of both the external `mac-release` entrypoint and its library before either can enter the secret-bearing process; any helper update requires an explicit local review and pin update.

Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
module github.com/steipete/goplaces

go 1.26.7
go 1.26.8

require github.com/alecthomas/kong v1.16.1
16 changes: 8 additions & 8 deletions scripts/bootstrap-go-toolchain.sh
Original file line number Diff line number Diff line change
Expand Up @@ -43,14 +43,14 @@ destination="$parent/$(basename "$destination")"

case "$($uname_bin -m)" in
arm64)
archive_name=go1.26.7.darwin-arm64.tar.gz
expected_size=64772572
expected_sha256=020a1e8224811be75163e920bc77e0926a1390a6aeea19bdcf23f74b9d749f6d
archive_name=go1.26.8.darwin-arm64.tar.gz
expected_size=64626620
expected_sha256=a012b25b571bd0138a03dcd25375ceba866fe5ca822f426d2c66a4de56fd3f4b
;;
x86_64)
archive_name=go1.26.7.darwin-amd64.tar.gz
expected_size=67852067
expected_sha256=92e8b34bff3c89ab16404c595669ac8cb004cc2f676dcbd1f5b87a6b8def3b47
archive_name=go1.26.8.darwin-amd64.tar.gz
expected_size=67759394
expected_sha256=186be014105aa6542b767d2c6ed5cca10a0214bdff809ef1724022a8c7894150
;;
*) die "unsupported macOS architecture" ;;
esac
Expand All @@ -61,7 +61,7 @@ if [[ "$testing" == 1 ]]; then
expected_size="${EXPECTED_ARCHIVE_SIZE:-$expected_size}"
expected_sha256="${EXPECTED_ARCHIVE_SHA256:-$expected_sha256}"
fi
[[ "$archive_url" == https://dl.google.com/go/go1.26.7.darwin-*.tar.gz ]] || die "unexpected toolchain URL"
[[ "$archive_url" == https://dl.google.com/go/go1.26.8.darwin-*.tar.gz ]] || die "unexpected toolchain URL"
[[ "$expected_size" =~ ^[1-9][0-9]*$ ]] || die "invalid pinned archive size"
[[ "$expected_sha256" =~ ^[0-9a-f]{64}$ ]] || die "invalid pinned archive digest"

Expand Down Expand Up @@ -95,7 +95,7 @@ $tar_bin -xzf "$archive" -C "$destination" --no-same-owner || die "toolchain ext
go_root="$destination/go"
[[ -d "$go_root" && ! -L "$go_root" ]] || die "toolchain root is invalid"
[[ -f "$go_root/bin/go" && ! -L "$go_root/bin/go" && -x "$go_root/bin/go" ]] || die "toolchain Go executable is invalid"
[[ "$(GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off "$go_root/bin/go" env GOVERSION)" == go1.26.7 ]] ||
[[ "$(GOENV=off GOTOOLCHAIN=local GOWORK=off GOTELEMETRY=off "$go_root/bin/go" env GOVERSION)" == go1.26.8 ]] ||
die "extracted toolchain version mismatch"

rm -f "$archive" "$members"
Expand Down
2 changes: 1 addition & 1 deletion scripts/rebuild-release-assets.sh
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ done
command -v "$go_bin" >/dev/null 2>&1 || die "go is required"
[[ -x "$git_bin" ]] || die "trusted Git executable is required"
command -v "$jq_bin" >/dev/null 2>&1 || die "jq is required"
[[ "$($go_bin env GOVERSION)" == go1.26.7 ]] || die "rebuild requires Go 1.26.7"
[[ "$($go_bin env GOVERSION)" == go1.26.8 ]] || die "rebuild requires Go 1.26.8"

source_dir="$(cd "$source_dir" && pwd -P)"
verified_dir="$(cd "$verified_dir" && pwd -P)"
Expand Down
4 changes: 2 additions & 2 deletions scripts/recheck-release-source.sh
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,8 @@ readonly sed_bin=/usr/bin/sed
readonly grep_bin=/usr/bin/grep
readonly official_origin=https://github.com/openclaw/goplaces.git
readonly system_path=/usr/bin:/bin:/usr/sbin:/sbin
readonly expected_go_version=go1.26.7
readonly expected_goreleaser_version=2.17.1
readonly expected_go_version=go1.26.8
readonly expected_goreleaser_version=2.18.1

die() {
echo "release source recheck: $*" >&2
Expand Down
Loading
Loading