[teamai] Push 87 resource(s) from XingfenD
This commit is contained in:
@@ -0,0 +1,430 @@
|
||||
name: AI Code Review (Claude)
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, ready_for_review]
|
||||
pull_request_review_comment:
|
||||
types: [created]
|
||||
pull_request_review:
|
||||
types: [submitted]
|
||||
|
||||
# Security note: these permissions apply to the entire repository, not just the current PR.
|
||||
# `pull-requests: write` allows the workflow to post, edit, and resolve comments on ANY pull request.
|
||||
# `actions: read` allows reading logs from ANY workflow run, which may contain sensitive output.
|
||||
# Scope risk by restricting the trigger to PRs from trusted contributors or protected branches,
|
||||
# and by never logging secrets in CI steps.
|
||||
permissions:
|
||||
contents: read
|
||||
issues: read
|
||||
pull-requests: write
|
||||
actions: read
|
||||
id-token: write
|
||||
|
||||
concurrency:
|
||||
group: claude-review-${{ github.event.pull_request.number || github.event.issue.number }}-${{ github.event_name }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
# ── Job 1: Code quality (suggestion-first) ──────────────────────────────────
|
||||
# Covers: style, naming, documentation
|
||||
quality:
|
||||
name: Review — Quality
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
# Skip bot PRs (Dependabot, Renovate, etc.)
|
||||
# Remove this filter if you want bots to get reviewed.
|
||||
if: ${{ github.event_name == 'pull_request' && !endsWith(github.event.pull_request.user.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Install Go skills
|
||||
run: npx skills add https://github.com/samber/cc-skills-golang -a claude-code --skill '*' -y --copy
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: true
|
||||
track_progress: true
|
||||
sticky_comment_header: "<!-- claude-review-quality -->"
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
claude_args: >-
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,mcp__context7__resolve-library-id,mcp__context7__query-docs,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
AUTHOR: ${{ github.event.pull_request.user.login }}
|
||||
|
||||
You are a senior Go engineer performing a focused code quality review.
|
||||
|
||||
Review this pull request.
|
||||
- Use `gh pr diff` to read the diff.
|
||||
- Use `gh pr view` to read description and metadata.
|
||||
- Use `mcp__github_inline_comment__create_inline_comment` with `confirmed: true`
|
||||
for every line-specific issue. Include a ```suggestion block when the fix is
|
||||
a direct 1:1 replacement of the selected lines.
|
||||
- Use `gh pr comment` only for a top-level summary.
|
||||
- Post nothing else. No chat output.
|
||||
|
||||
## Scope — apply these skill guidelines
|
||||
|
||||
- **Code style** — formatting, comment quality, idiomatic Go patterns (Skill("golang-code-style")).
|
||||
- **Naming** — packages, types, variables, functions, constants (Skill("golang-naming")).
|
||||
- **Documentation** — exported symbols, package-level docs, README impact (Skill("golang-documentation")).
|
||||
|
||||
## Priority — suggestion-first
|
||||
|
||||
These areas reflect style and readability, not correctness. Only raise an issue when it will confuse future readers, mislead consumers of an exported API, or make the codebase harder to navigate at scale. Do not flag formatting that `gofmt` handles automatically. Do not flag personal preferences when the code is otherwise clear.
|
||||
|
||||
## How to report
|
||||
|
||||
Every comment must:
|
||||
1. Name the specific problem (not just its symptom)
|
||||
2. Explain under what conditions it matters or fails
|
||||
3. Provide a concrete fix — renamed identifier, corrected code snippet, or safer pattern
|
||||
|
||||
Write short, concise comments. Only comment when there is a specific issue. Do not praise the good stuff. Before posting, verify the point was not already raised in a previous review comment.
|
||||
|
||||
Note: the PR branch is already checked out in the current working directory.
|
||||
|
||||
Check project guidelines: @./CLAUDE.md
|
||||
Check contributing guidelines: @./CONTRIBUTING.md
|
||||
Check project description: @./docs/project-summary.md
|
||||
|
||||
Label each comment: 🟡 **SUGGESTION**
|
||||
|
||||
# ── Job 2: Correctness (blocking-first) ─────────────────────────────────────
|
||||
# Covers: error handling, code safety, concurrency
|
||||
correctness:
|
||||
name: Review — Correctness
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
# Skip bot PRs (Dependabot, Renovate, etc.)
|
||||
# Remove this filter if you want bots to get reviewed.
|
||||
if: ${{ github.event_name == 'pull_request' && !endsWith(github.event.pull_request.user.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Install Go skills
|
||||
run: npx skills add https://github.com/samber/cc-skills-golang -a claude-code --skill '*' -y --copy
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: true
|
||||
track_progress: true
|
||||
sticky_comment_header: "<!-- claude-review-correctness -->"
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
claude_args: >-
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,mcp__context7__resolve-library-id,mcp__context7__query-docs,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
AUTHOR: ${{ github.event.pull_request.user.login }}
|
||||
|
||||
You are a senior Go engineer performing a focused correctness and safety review.
|
||||
|
||||
Review this pull request.
|
||||
- Use `gh pr diff` to read the diff.
|
||||
- Use `gh pr view` to read description and metadata.
|
||||
- Use `mcp__github_inline_comment__create_inline_comment` with `confirmed: true`
|
||||
for every line-specific issue. Include a ```suggestion block when the fix is
|
||||
a direct 1:1 replacement of the selected lines.
|
||||
- Use `gh pr comment` only for a top-level summary.
|
||||
- Post nothing else. No chat output.
|
||||
|
||||
## Scope — apply these skill guidelines
|
||||
|
||||
- **Error handling** — wrapping, sentinel errors, log-and-return, swallowed errors (Skill("golang-error-handling")).
|
||||
- **Code safety** — nil dereference, map/slice aliasing, integer overflows, uninitialized state (Skill("golang-safety")).
|
||||
- **Concurrency** — goroutine lifecycle, mutex usage, channel patterns, context propagation, data races (Skill("golang-concurrency")).
|
||||
|
||||
## Priority — blocking-first
|
||||
|
||||
A swallowed error, an unchecked nil, or an unsynchronized write can cause silent data corruption or production incidents — flag these even when the fix is non-trivial.
|
||||
|
||||
## How to report
|
||||
|
||||
Every comment must:
|
||||
1. Name the specific problem (not just its symptom)
|
||||
2. Explain under what conditions it matters or fails
|
||||
3. Provide a concrete fix — renamed identifier, corrected code snippet, or safer pattern
|
||||
|
||||
Write short, concise comments. Only comment when there is a specific issue. Do not praise the good stuff. Before posting, verify the point was not already raised in a previous review comment.
|
||||
|
||||
Note: the PR branch is already checked out in the current working directory.
|
||||
|
||||
Check project guidelines: @./CLAUDE.md
|
||||
Check contributing guidelines: @./CONTRIBUTING.md
|
||||
Check project description: @./docs/project-summary.md
|
||||
|
||||
Label each comment with its severity:
|
||||
- 🔴 **BLOCKING** — definite bug, data race, or correctness failure; must be fixed before merge.
|
||||
- 🟠 **IMPORTANT** — significant risk that requires unusual conditions to manifest; strongly recommended to fix.
|
||||
- 🟡 **SUGGESTION** — defensive improvement with low-probability failure mode or subtle edge case.
|
||||
|
||||
# ── Job 3: Security & dependencies (blocking-first) ─────────────────────────
|
||||
# Covers: security, dependency health
|
||||
security:
|
||||
name: Review — Security & Dependencies
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
# Skip bot PRs (Dependabot, Renovate, etc.)
|
||||
# Remove this filter if you want bots to get reviewed.
|
||||
if: ${{ github.event_name == 'pull_request' && !endsWith(github.event.pull_request.user.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Install Go skills
|
||||
run: npx skills add https://github.com/samber/cc-skills-golang -a claude-code --skill '*' -y --copy
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: true
|
||||
track_progress: true
|
||||
sticky_comment_header: "<!-- claude-review-security -->"
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
claude_args: >-
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,mcp__context7__resolve-library-id,mcp__context7__query-docs,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
AUTHOR: ${{ github.event.pull_request.user.login }}
|
||||
|
||||
You are a senior Go security engineer performing a focused security and dependency review.
|
||||
|
||||
Review this pull request.
|
||||
- Use `gh pr diff` to read the diff.
|
||||
- Use `gh pr view` to read description and metadata.
|
||||
- Use `mcp__github_inline_comment__create_inline_comment` with `confirmed: true`
|
||||
for every line-specific issue. Include a ```suggestion block when the fix is
|
||||
a direct 1:1 replacement of the selected lines.
|
||||
- Use `gh pr comment` only for a top-level summary.
|
||||
- Post nothing else. No chat output.
|
||||
|
||||
## Scope — apply these skill guidelines
|
||||
|
||||
- **Security** — injection, auth, crypto misuse, sensitive data exposure, input validation (Skill("golang-security")).
|
||||
- **Dependencies** — new imports, CVE history, abandoned packages, `replace` directives (Skill("golang-dependency-management")).
|
||||
|
||||
## Priority — blocking-first
|
||||
|
||||
Security issues and supply-chain risks must be flagged before style or quality concerns. A single unvalidated input or a weak PRNG can open a critical vulnerability — do not downgrade these findings.
|
||||
|
||||
## How to report
|
||||
|
||||
Every comment must:
|
||||
1. Name the specific problem (not just its symptom)
|
||||
2. Explain under what conditions it matters or fails
|
||||
3. Provide a concrete fix — renamed identifier, corrected code snippet, or safer pattern
|
||||
|
||||
Write short, concise comments. Only comment when there is a specific issue. Do not praise the good stuff. Before posting, verify the point was not already raised in a previous review comment.
|
||||
|
||||
Note: the PR branch is already checked out in the current working directory.
|
||||
|
||||
Check project guidelines: @./CLAUDE.md
|
||||
Check contributing guidelines: @./CONTRIBUTING.md
|
||||
Check project description: @./docs/project-summary.md
|
||||
|
||||
Label each comment with its severity:
|
||||
- 🔴 **BLOCKING** — exploitable vulnerability or high-risk dependency; must be fixed before merge.
|
||||
- 🟠 **IMPORTANT** — significant risk that requires specific conditions; strongly recommended.
|
||||
- 🟡 **SUGGESTION** — defense-in-depth improvement; optional but worthwhile.
|
||||
|
||||
# ── Job 4: Tests, performance, observability & modernization ─────────────────
|
||||
# Covers: tests, performance, observability, modernize
|
||||
quality-depth:
|
||||
name: Review — Tests, Performance & Observability
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
# Skip bot PRs (Dependabot, Renovate, etc.)
|
||||
# Remove this filter if you want bots to get reviewed.
|
||||
if: ${{ github.event_name == 'pull_request' && !endsWith(github.event.pull_request.user.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Install Go skills
|
||||
run: npx skills add https://github.com/samber/cc-skills-golang -a claude-code --skill '*' -y --copy
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: true
|
||||
track_progress: true
|
||||
sticky_comment_header: "<!-- claude-review-quality-depth -->"
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
claude_args: >-
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,mcp__context7__resolve-library-id,mcp__context7__query-docs,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
AUTHOR: ${{ github.event.pull_request.user.login }}
|
||||
|
||||
You are a senior Go engineer reviewing for test coverage, performance, observability, and code modernization.
|
||||
|
||||
Review this pull request.
|
||||
- Use `gh pr diff` to read the diff.
|
||||
- Use `gh pr view` to read description and metadata.
|
||||
- Use `mcp__github_inline_comment__create_inline_comment` with `confirmed: true`
|
||||
for every line-specific issue. Include a ```suggestion block when the fix is
|
||||
a direct 1:1 replacement of the selected lines.
|
||||
- Use `gh pr comment` only for a top-level summary.
|
||||
- Post nothing else. No chat output.
|
||||
|
||||
## Scope — apply these skill guidelines
|
||||
|
||||
- **Tests** — coverage of new code, test quality, table-driven tests, use of t.Helper() (Skill("golang-testing")).
|
||||
- **Performance** — unnecessary allocations, inefficient data structures, missing bounds (Skill("golang-performance")).
|
||||
- **Observability** — logging, metrics, tracing added for new code paths (Skill("golang-observability")).
|
||||
- **Modernize code** — outdated patterns replaced with Go 1.21+ idioms (Skill("golang-modernize")).
|
||||
|
||||
## Priority
|
||||
|
||||
- **Tests** and **Performance** are important — flag missing coverage on new exported paths and obvious allocation hot-spots on critical paths.
|
||||
- **Observability** and **Modernize** are suggestion-first — raise only when the gap is material or the pattern is clearly outdated.
|
||||
|
||||
## How to report
|
||||
|
||||
Every comment must:
|
||||
1. Name the specific problem (not just its symptom)
|
||||
2. Explain under what conditions it matters or fails
|
||||
3. Provide a concrete fix — renamed identifier, corrected code snippet, or safer pattern
|
||||
|
||||
Write short, concise comments. Only comment when there is a specific issue. Do not praise the good stuff. Before posting, verify the point was not already raised in a previous review comment.
|
||||
|
||||
Note: the PR branch is already checked out in the current working directory.
|
||||
|
||||
Check project guidelines: @./CLAUDE.md
|
||||
Check contributing guidelines: @./CONTRIBUTING.md
|
||||
Check project description: @./docs/project-summary.md
|
||||
|
||||
Label each comment with its severity:
|
||||
- 🟠 **IMPORTANT** — missing test for a critical exported path; allocation hot-spot on a latency-sensitive path.
|
||||
- 🟡 **SUGGESTION** — observability gap, modernization opportunity, or minor test quality improvement.
|
||||
|
||||
# ── Job 5: CI failure diagnosis ──────────────────────────────────────────────
|
||||
# Waits for all review jobs to finish, then diagnoses any failures and suggests fixes.
|
||||
ci-diagnosis:
|
||||
name: Review — CI Failure Diagnosis
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
needs: [quality, correctness, security, quality-depth]
|
||||
if: ${{ always() && github.event_name == 'pull_request' && !endsWith(github.event.pull_request.user.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: true
|
||||
track_progress: true
|
||||
sticky_comment_header: "<!-- claude-review-ci-diagnosis -->"
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
claude_args: >-
|
||||
--allowedTools "Bash(gh pr comment:*),Bash(gh pr view:*),Bash(gh run view:*),Bash(gh run list:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
WORKFLOW RUN ID: ${{ github.run_id }}
|
||||
|
||||
You are a senior Go engineer diagnosing CI failures on a pull request.
|
||||
|
||||
Check whether any of the parallel review jobs (quality, correctness, security, quality-depth)
|
||||
failed in this workflow run. If all jobs succeeded, post nothing and exit.
|
||||
|
||||
If any job failed:
|
||||
- Use `gh run view` to inspect the failed job logs and identify the root cause.
|
||||
- Post a single `gh pr comment` summarizing:
|
||||
1. Which job(s) failed and why (log excerpt).
|
||||
2. Concrete steps to fix the failure (configuration change, missing secret, infra issue).
|
||||
- Post nothing else. No chat output.
|
||||
|
||||
# ── Job 6: Discuss review comments ──────────────────────────────────────────
|
||||
# Triggered when a human posts a review comment or submits a review.
|
||||
# Replies to offer a counter-argument when warranted — stays concise.
|
||||
discuss:
|
||||
name: Review — Discuss
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
if: ${{ (github.event_name == 'pull_request_review_comment' || github.event_name == 'pull_request_review') && !endsWith(github.event.sender.login, '[bot]') }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
show_full_output: true
|
||||
use_sticky_comment: false
|
||||
track_progress: false
|
||||
claude_args: >-
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr view:*),Bash(gh pr diff:*)"
|
||||
prompt: |
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number }}
|
||||
|
||||
You are a senior Go engineer participating in a code review discussion.
|
||||
|
||||
A human just posted a review comment or submitted a review on this PR.
|
||||
Read the comment thread and decide whether to reply.
|
||||
|
||||
Reply ONLY if:
|
||||
- The comment contains a factual mistake about Go semantics, the standard library, or a third-party package.
|
||||
- The proposed change would introduce a bug, a performance regression, or a security issue.
|
||||
- A brief clarification would unblock the discussion.
|
||||
|
||||
Do NOT reply if:
|
||||
- The comment is a style preference and both approaches are valid.
|
||||
- The author has already acknowledged the feedback.
|
||||
- A debate is already in progress — let it resolve naturally.
|
||||
- You already replied to this thread.
|
||||
|
||||
When you reply: be short and direct. One or two sentences maximum. State the technical
|
||||
fact. If the author disagrees after your reply, drop the thread.
|
||||
|
||||
You may also add a 👍 reaction to a comment to acknowledge it without adding another
|
||||
comment — prefer this when the discussion is resolved or the point is already clear.
|
||||
|
||||
Use `mcp__github_inline_comment__create_inline_comment` to reply inline when the comment
|
||||
is line-specific, otherwise use `gh pr comment`. Post nothing else. No chat output.
|
||||
@@ -0,0 +1,9 @@
|
||||
coverage:
|
||||
status:
|
||||
project:
|
||||
default:
|
||||
target: 80%
|
||||
threshold: 2%
|
||||
patch:
|
||||
default:
|
||||
target: 80%
|
||||
@@ -0,0 +1,8 @@
|
||||
name: "CodeQL config"
|
||||
|
||||
queries:
|
||||
- uses: security-and-quality
|
||||
|
||||
query-filters:
|
||||
- exclude:
|
||||
id: go/unused-result
|
||||
+61
@@ -0,0 +1,61 @@
|
||||
<!-- Prerequisites:
|
||||
The skills CLI (listed in the frontmatter install block) can be used to copy skills locally:
|
||||
npx skills add https://github.com/samber/cc-skills-golang --agent github-copilot --skill '*' -y --copy
|
||||
ln -s .agents .copilot
|
||||
Then copy this file to .github/copilot-instructions.md
|
||||
-->
|
||||
|
||||
# Go Code Review Instructions
|
||||
|
||||
You are a senior Go engineer reviewing a pull request. Review the diff thoroughly and provide actionable, prioritized feedback.
|
||||
|
||||
The available skills can be discovered from the local skill files:
|
||||
|
||||
find .copilot/skills -type f -name SKILL.md -print0 \
|
||||
| xargs -0 yq -o=json \
|
||||
| jq -r '{name, description}'
|
||||
|
||||
Relevant skills should be loaded before reviewing the diff.
|
||||
|
||||
## Scope of Review
|
||||
|
||||
Cover each area below. Where a dedicated skill is listed, apply its guidance.
|
||||
|
||||
- **Code style** — formatting, comment quality, idiomatic Go patterns (`.copilot/skills/golang-code-style/SKILL.md`)
|
||||
- **Naming** — packages, types, variables, functions, constants (`.copilot/skills/golang-naming/SKILL.md`)
|
||||
- **Error handling** — wrapping, sentinel errors, log-and-return, swallowed errors (`.copilot/skills/golang-error-handling/SKILL.md`)
|
||||
- **Concurrency** — goroutine lifecycle, mutex usage, channel patterns, context propagation, data races (`.copilot/skills/golang-concurrency/SKILL.md`)
|
||||
- **Code safety** — nil dereference, map/slice aliasing, integer overflows, uninitialized state (`.copilot/skills/golang-safety/SKILL.md`)
|
||||
- **Tests** — coverage of new code, test quality, table-driven tests, use of t.Helper() (`.copilot/skills/golang-testing/SKILL.md`)
|
||||
- **Performance** — unnecessary allocations, inefficient data structures, missing bounds (`.copilot/skills/golang-performance/SKILL.md`)
|
||||
- **Security** — injection, auth, crypto misuse, sensitive data exposure, input validation (`.copilot/skills/golang-security/SKILL.md`)
|
||||
- **Dependencies** — new imports, license compatibility, known vulnerabilities (`.copilot/skills/golang-dependency-management/SKILL.md`)
|
||||
- **Documentation** — exported symbols, package docs, README impact (`.copilot/skills/golang-documentation/SKILL.md`)
|
||||
- **Observability** — logging, metrics, tracing added for new code paths (`.copilot/skills/golang-observability/SKILL.md`)
|
||||
- **Modernize code** — outdated patterns replaced with Go 1.21+ idioms (`.copilot/skills/golang-modernize/SKILL.md`)
|
||||
|
||||
## Review Priority
|
||||
|
||||
Not all areas carry the same risk. Apply this order when time or API budget is limited:
|
||||
|
||||
- **Blocking-first areas** (look for bugs and vulnerabilities before style): Security, Code safety, Error handling, Concurrency
|
||||
- **Important areas** (significant quality impact): Tests, Performance, Dependencies
|
||||
- **Suggestion-first areas** (raise only when notably wrong): Code style, Naming, Documentation, Observability, Modernize code
|
||||
|
||||
## How to Report Issues
|
||||
|
||||
For each issue found:
|
||||
|
||||
- Reference the exact file and line number.
|
||||
- Explain what is wrong and why it matters.
|
||||
- Provide a concrete fix or example.
|
||||
|
||||
Classify severity:
|
||||
|
||||
- 🔴 **BLOCKING** — bug, vulnerability, data race, or correctness issue; must be fixed before merge.
|
||||
- 🟠 **IMPORTANT** — significant quality or maintainability concern; strongly recommended.
|
||||
- 🟡 **SUGGESTION** — style, naming, or minor improvement; optional but worthwhile.
|
||||
|
||||
Use inline comments on the specific diff line when possible. For concerns not tied to a specific line, post a PR-level summary.
|
||||
|
||||
Write short, concise comments. Only comment when there is a specific issue — do not praise the good stuff. If you have nothing to say, post nothing. Before posting, verify the point was not already raised in a previous review comment.
|
||||
@@ -0,0 +1,28 @@
|
||||
name: Dependabot Auto-Merge
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
auto-merge:
|
||||
name: Auto-Merge
|
||||
runs-on: ubuntu-latest
|
||||
if: github.actor == 'dependabot[bot]'
|
||||
|
||||
steps:
|
||||
- name: Fetch Dependabot metadata
|
||||
id: metadata
|
||||
uses: dependabot/fetch-metadata@v2
|
||||
with:
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Auto-merge minor and patch updates
|
||||
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
|
||||
run: gh pr merge --auto --squash "$PR_URL"
|
||||
env:
|
||||
PR_URL: ${{ github.event.pull_request.html_url }}
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
@@ -0,0 +1,30 @@
|
||||
version: 2
|
||||
updates:
|
||||
# Go modules
|
||||
- package-ecosystem: gomod
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
day: monday
|
||||
labels: ["dependencies", "go"]
|
||||
open-pull-requests-limit: 10
|
||||
groups:
|
||||
go-minor-patch:
|
||||
update-types: [minor, patch]
|
||||
|
||||
# GitHub Actions
|
||||
- package-ecosystem: github-actions
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
labels: ["dependencies", "ci"]
|
||||
groups:
|
||||
actions:
|
||||
patterns: ["*"]
|
||||
|
||||
# Docker (if applicable)
|
||||
- package-ecosystem: docker
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
labels: ["dependencies", "docker"]
|
||||
@@ -0,0 +1,96 @@
|
||||
name: Docker
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
tags: ["v*"]
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
container-scan:
|
||||
name: Container Scan
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: write
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Build image
|
||||
run: docker build -t myapp:ci .
|
||||
|
||||
- name: Run Trivy
|
||||
uses: aquasecurity/trivy-action@v0.35.0
|
||||
with:
|
||||
image-ref: myapp:ci
|
||||
format: sarif
|
||||
output: trivy-results.sarif
|
||||
severity: CRITICAL,HIGH
|
||||
exit-code: '1'
|
||||
|
||||
- name: Upload Trivy results
|
||||
if: always()
|
||||
uses: github/codeql-action/upload-sarif@v4
|
||||
with:
|
||||
sarif_file: trivy-results.sarif
|
||||
|
||||
docker:
|
||||
name: Build & Push
|
||||
runs-on: ubuntu-latest
|
||||
needs: container-scan
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
attestations: write
|
||||
id-token: write
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v3
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Log in to GitHub Container Registry
|
||||
if: github.event_name != 'pull_request'
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
if: github.event_name != 'pull_request'
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Extract metadata
|
||||
id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
images: |
|
||||
ghcr.io/${{ github.repository }}
|
||||
docker.io/${{ github.repository }}
|
||||
tags: |
|
||||
type=semver,pattern={{version}}
|
||||
type=semver,pattern={{major}}.{{minor}}
|
||||
type=semver,pattern={{major}}
|
||||
type=ref,event=branch
|
||||
type=sha
|
||||
|
||||
- name: Build and push
|
||||
id: build
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
provenance: mode=max
|
||||
sbom: true
|
||||
push: ${{ github.event_name != 'pull_request' }}
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
@@ -0,0 +1,31 @@
|
||||
version: 2
|
||||
|
||||
builds:
|
||||
- env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- linux
|
||||
- darwin
|
||||
- windows
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
ldflags:
|
||||
- -s -w
|
||||
- -X main.version={{.Version}}
|
||||
- -X main.commit={{.Commit}}
|
||||
|
||||
archives:
|
||||
- format: tar.gz
|
||||
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}"
|
||||
format_overrides:
|
||||
- goos: windows
|
||||
format: zip
|
||||
|
||||
checksum:
|
||||
name_template: checksums.txt
|
||||
|
||||
changelog:
|
||||
sort: asc
|
||||
filters:
|
||||
exclude: ["^docs", "^test", "^ci", "^chore", "^style"]
|
||||
@@ -0,0 +1,9 @@
|
||||
version: 2
|
||||
|
||||
builds:
|
||||
- skip: true
|
||||
|
||||
changelog:
|
||||
sort: asc
|
||||
filters:
|
||||
exclude: ["^docs:", "^test:", "^ci:", "^chore:"]
|
||||
@@ -0,0 +1,30 @@
|
||||
version: 2
|
||||
|
||||
builds:
|
||||
- id: api
|
||||
main: ./cmd/api
|
||||
binary: api
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- linux
|
||||
- darwin
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
|
||||
- id: worker
|
||||
main: ./cmd/worker
|
||||
binary: worker
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- linux
|
||||
- darwin
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
|
||||
archives:
|
||||
- format: tar.gz
|
||||
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}"
|
||||
@@ -0,0 +1,53 @@
|
||||
name: Integration Tests
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
integration:
|
||||
name: Integration Tests
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
services:
|
||||
postgres:
|
||||
image: postgres:18-alpine
|
||||
env:
|
||||
POSTGRES_USER: test
|
||||
POSTGRES_PASSWORD: test
|
||||
POSTGRES_DB: testdb
|
||||
ports:
|
||||
- 5432:5432
|
||||
options: >-
|
||||
--health-cmd pg_isready
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
ports:
|
||||
- 6379:6379
|
||||
options: >-
|
||||
--health-cmd "redis-cli ping"
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Run integration tests
|
||||
run: go test -v -race -tags=integration -count=1 ./...
|
||||
env:
|
||||
DATABASE_URL: postgres://test:test@localhost:5432/testdb?sslmode=disable
|
||||
REDIS_URL: redis://localhost:6379
|
||||
@@ -0,0 +1,31 @@
|
||||
name: Lint
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
lint:
|
||||
name: Lint
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Run go vet
|
||||
run: go vet ./...
|
||||
|
||||
- name: golangci-lint
|
||||
uses: golangci/golangci-lint-action@v9
|
||||
with:
|
||||
version: latest
|
||||
args: --timeout 5m
|
||||
@@ -0,0 +1,31 @@
|
||||
name: Release
|
||||
|
||||
on:
|
||||
push:
|
||||
tags: ["v*"]
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Run GoReleaser
|
||||
uses: goreleaser/goreleaser-action@v7
|
||||
with:
|
||||
version: "~> v2"
|
||||
args: release --clean
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
@@ -0,0 +1,22 @@
|
||||
{
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"extends": [
|
||||
"config:recommended"
|
||||
],
|
||||
"postUpdateOptions": [
|
||||
"gomodTidy"
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"matchManagers": ["gomod"],
|
||||
"matchUpdateTypes": ["minor", "patch"],
|
||||
"automerge": true,
|
||||
"groupName": "go minor/patch dependencies"
|
||||
},
|
||||
{
|
||||
"matchManagers": ["github-actions"],
|
||||
"automerge": true,
|
||||
"groupName": "github actions"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,82 @@
|
||||
name: Security
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: write
|
||||
|
||||
jobs:
|
||||
govulncheck:
|
||||
name: Vulnerability Check
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Run govulncheck
|
||||
uses: golang/govulncheck-action@v1
|
||||
|
||||
gosec:
|
||||
name: gosec
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Run gosec
|
||||
uses: securego/gosec@v2
|
||||
with:
|
||||
args: -no-fail -fmt sarif -out gosec-results.sarif ./...
|
||||
|
||||
- name: Upload gosec results
|
||||
if: always()
|
||||
uses: github/codeql-action/upload-sarif@v4
|
||||
with:
|
||||
sarif_file: gosec-results.sarif
|
||||
|
||||
codeql:
|
||||
name: CodeQL
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@v4
|
||||
with:
|
||||
languages: go
|
||||
config-file: .github/codeql/codeql-config.yml
|
||||
|
||||
- name: Autobuild
|
||||
uses: github/codeql-action/autobuild@v4
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v4
|
||||
|
||||
bearer:
|
||||
name: Bearer
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Bearer Security Scan
|
||||
uses: bearer/bearer-action@v2
|
||||
with:
|
||||
format: sarif
|
||||
output: bearer-results.sarif
|
||||
|
||||
- name: Upload Bearer results
|
||||
if: always()
|
||||
uses: github/codeql-action/upload-sarif@v4
|
||||
with:
|
||||
sarif_file: bearer-results.sarif
|
||||
@@ -0,0 +1,53 @@
|
||||
name: Tests
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: Test (Go ${{ matrix.go }})
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
go:
|
||||
- "1.25"
|
||||
- "1.26"
|
||||
- "stable"
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: ${{ matrix.go }}
|
||||
|
||||
- name: Verify dependencies
|
||||
run: |
|
||||
go mod verify
|
||||
go mod download
|
||||
|
||||
- name: Check go mod tidy
|
||||
run: |
|
||||
go mod tidy
|
||||
git diff --exit-code go.mod go.sum
|
||||
|
||||
- name: Build
|
||||
run: go build ./...
|
||||
|
||||
- name: Run tests
|
||||
run: go test -v -race -shuffle=on -coverprofile=coverage.out ./...
|
||||
|
||||
- name: Upload coverage
|
||||
if: matrix.go == 'stable'
|
||||
uses: codecov/codecov-action@v5
|
||||
with:
|
||||
files: ./coverage.out
|
||||
fail_ci_if_error: false
|
||||
token: ${{ secrets.CODECOV_TOKEN }}
|
||||
Reference in New Issue
Block a user