From 07d436300263d497a114853973ea43437118c291 Mon Sep 17 00:00:00 2001 From: Bo-Yi Wu Date: Mon, 28 Sep 2026 21:51:53 +0800 Subject: [PATCH 1/2] build(go)!: require Go 1.26.8 and test Go 1.27 - Require Go 1.26.8 and validate Go 1.26 and 1.27 in CI - Align lint and CodeQL toolchains and enforce Trivy security checks - Build example modules with both supported Go versions - Validate release configuration with GoReleaser v2 - Reuse test fixture constants to satisfy goconst BREAKING CHANGE: Go 1.26.8 or newer is required. Upgrade the Go toolchain before building this module. --- .github/workflows/codeql.yaml | 6 +++++ .github/workflows/go.yml | 42 +++++++++++++++++++++++++------- .github/workflows/goreleaser.yml | 3 ++- .goreleaser.yaml | 2 ++ _example/example01/go.mod | 2 +- _example/example02/go.mod | 2 +- benchmark_test.go | 2 +- go.mod | 2 +- ring_test.go | 21 ++++++++++------ 9 files changed, 60 insertions(+), 22 deletions(-) diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index ad1acfd..c062ce1 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -39,6 +39,12 @@ jobs: - name: Checkout repository uses: actions/checkout@v7 + - name: Set up Go + uses: actions/setup-go@v7 + with: + go-version-file: go.mod + check-latest: true + # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL uses: github/codeql-action/init@v4 diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 03ad171..9b2894a 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -17,6 +17,9 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +env: + GOTOOLCHAIN: local + jobs: lint: runs-on: ubuntu-latest @@ -33,14 +36,15 @@ jobs: - name: Setup golangci-lint uses: golangci/golangci-lint-action@v9 with: - version: v2.7 + version: v2.14.0 args: --verbose test: strategy: + fail-fast: false matrix: os: [ubuntu-latest] - go: [1.25, 1.26] + go: ["1.26.x", "1.27.x"] include: - os: ubuntu-latest go-build: ~/.cache/go-build @@ -50,24 +54,25 @@ jobs: GO111MODULE: on GOPROXY: https://proxy.golang.org steps: - - name: Set up Go ${{ matrix.go }} - uses: actions/setup-go@v7 - with: - go-version: ${{ matrix.go }} - - name: Checkout Code uses: actions/checkout@v7 with: ref: ${{ github.ref }} + - name: Set up Go ${{ matrix.go }} + uses: actions/setup-go@v7 + with: + go-version: ${{ matrix.go }} + check-latest: true + - uses: actions/cache@v6 with: path: | ${{ matrix.go-build }} ~/go/pkg/mod - key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }} + key: ${{ runner.os }}-go-${{ matrix.go }}-${{ hashFiles('**/go.sum') }} restore-keys: | - ${{ runner.os }}-go- + ${{ runner.os }}-go-${{ matrix.go }}- - name: Run Tests run: | go test -race -v -covermode=atomic -coverprofile=coverage.out @@ -76,7 +81,26 @@ jobs: run: | go test -v -run=^$ -count 5 -benchmem -bench . ./... + - name: Build example modules + run: | + find _example -name go.mod -print0 | while IFS= read -r -d '' mod; do + (cd "$(dirname "$mod")" && go build -mod=readonly ./...) + done + - name: Upload coverage to Codecov uses: codecov/codecov-action@v7 with: flags: ${{ matrix.os }},go-${{ matrix.go }} + + vulnerability-scanning: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + - name: Run Trivy vulnerability scanner in repo mode + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: 'fs' + ignore-unfixed: true + format: 'table' + exit-code: '1' + severity: 'CRITICAL,HIGH,MEDIUM' diff --git a/.github/workflows/goreleaser.yml b/.github/workflows/goreleaser.yml index 30053de..283786d 100644 --- a/.github/workflows/goreleaser.yml +++ b/.github/workflows/goreleaser.yml @@ -19,7 +19,8 @@ jobs: - name: Set up Go uses: actions/setup-go@v7 with: - go-version: "^1" + go-version-file: go.mod + check-latest: true - name: Run GoReleaser uses: goreleaser/goreleaser-action@v7 with: diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 72e3918..10150f8 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -1,3 +1,5 @@ +version: 2 + builds: - # If true, skip the build. # Useful for library projects. diff --git a/_example/example01/go.mod b/_example/example01/go.mod index 6de3078..b3727f0 100644 --- a/_example/example01/go.mod +++ b/_example/example01/go.mod @@ -1,6 +1,6 @@ module example -go 1.25.0 +go 1.26.8 require ( github.com/golang-queue/contrib v1.1.0 diff --git a/_example/example02/go.mod b/_example/example02/go.mod index 6de3078..b3727f0 100644 --- a/_example/example02/go.mod +++ b/_example/example02/go.mod @@ -1,6 +1,6 @@ module example -go 1.25.0 +go 1.26.8 require ( github.com/golang-queue/contrib v1.1.0 diff --git a/benchmark_test.go b/benchmark_test.go index 29836ce..1eae758 100644 --- a/benchmark_test.go +++ b/benchmark_test.go @@ -76,7 +76,7 @@ func BenchmarkQueue(b *testing.B) { b.ResetTimer() m := job.NewMessage(&mockMessage{ - message: "foo", + message: testMessageFoo, }) for n := 0; n < b.N; n++ { diff --git a/go.mod b/go.mod index 032d094..2aaec2a 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/golang-queue/queue -go 1.25 +go 1.26.8 require ( github.com/appleboy/com v1.2.0 diff --git a/ring_test.go b/ring_test.go index b264c21..fc6eab0 100644 --- a/ring_test.go +++ b/ring_test.go @@ -17,6 +17,11 @@ import ( "go.uber.org/mock/gomock" ) +const ( + testMessageFoo = "foo" + testMessageTest = "test" +) + func TestMaxCapacity(t *testing.T) { w := NewRing(WithQueueSize(2)) @@ -30,7 +35,7 @@ func TestMaxCapacity(t *testing.T) { func TestCustomFuncAndWait(t *testing.T) { m := mockMessage{ - message: "foo", + message: testMessageFoo, } w := NewRing( WithFn(func(ctx context.Context, m core.TaskMessage) error { @@ -59,7 +64,7 @@ func TestCustomFuncAndWait(t *testing.T) { func TestEnqueueJobAfterShutdown(t *testing.T) { m := mockMessage{ - message: "foo", + message: testMessageFoo, } w := NewRing() q, err := NewQueue( @@ -79,7 +84,7 @@ func TestEnqueueJobAfterShutdown(t *testing.T) { func TestJobReachTimeout(t *testing.T) { m := mockMessage{ - message: "foo", + message: testMessageFoo, } w := NewRing( WithFn(func(ctx context.Context, m core.TaskMessage) error { @@ -112,7 +117,7 @@ func TestJobReachTimeout(t *testing.T) { func TestCancelJobAfterShutdown(t *testing.T) { m := mockMessage{ - message: "foo", + message: testMessageFoo, } w := NewRing( WithLogger(NewEmptyLogger()), @@ -189,7 +194,7 @@ func TestGoroutineLeak(t *testing.T) { func TestGoroutinePanic(t *testing.T) { m := mockMessage{ - message: "foo", + message: testMessageFoo, } w := NewRing( WithFn(func(ctx context.Context, m core.TaskMessage) error { @@ -512,7 +517,7 @@ func TestErrNoTaskInQueue(t *testing.T) { func BenchmarkRingQueue(b *testing.B) { b.Run("queue and request operations", func(b *testing.B) { w := NewRing(WithQueueSize(1000)) - m := mockMessage{message: "test"} + m := mockMessage{message: testMessageTest} b.ResetTimer() b.RunParallel(func(pb *testing.PB) { @@ -525,7 +530,7 @@ func BenchmarkRingQueue(b *testing.B) { b.Run("concurrent queue operations", func(b *testing.B) { w := NewRing(WithQueueSize(1000)) - m := mockMessage{message: "test"} + m := mockMessage{message: testMessageTest} b.ResetTimer() b.RunParallel(func(pb *testing.PB) { @@ -537,7 +542,7 @@ func BenchmarkRingQueue(b *testing.B) { b.Run("resize operations", func(b *testing.B) { w := NewRing() - m := mockMessage{message: "test"} + m := mockMessage{message: testMessageTest} b.ResetTimer() for i := 0; i < b.N; i++ { From af8fc534c0d2ae7a1505580a800669ebd19b9046 Mon Sep 17 00:00:00 2001 From: Bo-Yi Wu Date: Tue, 29 Sep 2026 21:08:43 +0800 Subject: [PATCH 2/2] ci(go): simplify Go version matrix --- .github/workflows/go.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 9b2894a..513d4f1 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -44,7 +44,7 @@ jobs: fail-fast: false matrix: os: [ubuntu-latest] - go: ["1.26.x", "1.27.x"] + go: ["1.26", "1.27"] include: - os: ubuntu-latest go-build: ~/.cache/go-build