Files
LibreMail-Bug-Report-Ingest/.github/workflows/ci.yml
T
JMR-devandClaude Opus 4.8 f27ad42c24 #26 Pin Go 1.25 + TinyGo 0.41.1 so the Wasm build compiles
TinyGo 0.41.1's bundled net/http override (roundtrip_js.go) fails to
compile against the Go 1.26 stdlib:

  net/http/roundtrip_js.go:73:12: t.roundTrip undefined (type *Transport
  has no field or method roundTrip, but does have method RoundTrip)

This is tinygo-org/tinygo#5467 (closed 2026-06-20, but not in any tagged
TinyGo release as of 0.41.1, released 2026-04-22). Go 1.25.x is the
newest line TinyGo 0.41.1 fully supports; syumai/workers v0.33.0 needs
only go 1.21.3 and the handler uses only net/http + encoding/json, so
downgrading is safe:

- go.mod: go 1.26.2 -> go 1.25.0 (so GOTOOLCHAIN won't auto-upgrade past
  what TinyGo supports)
- ci.yml: setup-go go-version 1.26 -> 1.25 (TinyGo pin stays 0.41.1)
- README: document the pinned TinyGo/Go matrix and the #5467 rationale

go vet ./..., go test ./..., and actionlint stay green locally.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:42:17 -05:00

93 lines
3.4 KiB
YAML

# Continuous integration for the LibreMail bug-report ingest Worker.
#
# Runs on every pull request targeting main and on every push to main. One job
# vets and tests the build-tag-free Go core and then builds the TinyGo/Wasm
# Cloudflare Worker end to end, so a red check reliably means "do not merge".
#
# Supply-chain note: every action (first- and third-party) is pinned to a full
# commit SHA with a trailing "# vX.Y.Z" comment tracking the human-readable
# release, matching the style of .github/workflows/autoupdate.yml.
name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
# Least privilege: the job only needs read access to check the repo out.
permissions:
contents: read
# Cancel superseded runs for the same ref so rapid pushes don't pile up.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
ci:
name: ci
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
# Pinned to Go 1.25 (not 1.26) to match TinyGo. TinyGo 0.41.1's bundled
# net/http override (roundtrip_js.go) fails to compile against the Go 1.26
# stdlib -- "t.roundTrip undefined ... has method RoundTrip"
# (tinygo-org/tinygo#5467, unfixed in any tagged TinyGo release as of
# 0.41.1). Go 1.25.x is the newest line TinyGo 0.41.1 fully supports. The
# go.mod `go` directive is pinned to 1.25 too, so GOTOOLCHAIN won't
# auto-upgrade. go vet/test also run on this version.
- name: Set up Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version: '1.25'
# TinyGo is needed only for the Wasm Worker build (pnpm run build).
# install-binaryen (default true) provides wasm-opt, which TinyGo invokes
# for the -target wasm build.
- name: Set up TinyGo
uses: acifani/setup-tinygo@dd8a7075d951a7595b2ef2123ed0ab1af0c13e56 # v3.0.0
with:
tinygo-version: '0.41.1'
- name: Set up pnpm
uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9
with:
version: '10'
# setup-node's pnpm cache needs pnpm already on PATH (hence after
# action-setup); it caches the pnpm store keyed on pnpm-lock.yaml.
- name: Set up Node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '22'
cache: pnpm
- name: Install Node dependencies
run: pnpm install --frozen-lockfile
- name: Vet Go
run: go vet ./...
- name: Test Go
run: go test ./...
# Robust to future modules: ticket #2 will add an infra/ Go module. Guarded
# with a dir check so this is a no-op until infra/go.mod exists.
- name: Vet and test infra module (if present)
run: |
if [ -f infra/go.mod ]; then
echo "infra/go.mod present; running go vet and go test in infra/"
( cd infra && go vet ./... && go test ./... )
else
echo "infra/go.mod not present; skipping (no-op until ticket #2)"
fi
# Confirms the Wasm Worker builds end to end: workers-assets-gen emits the
# JS shim and TinyGo compiles ./worker into build/app.wasm.
- name: Build Wasm Worker
run: pnpm run build