ci: add Go lint + test + vuln scanning for antd-go - #112
Merged
Conversation
antd-go ships as a v1.0 SDK but has had no CI coverage — the existing
ci.yml path filter (antd/**, antd-rust/**) skips it entirely. Sibling
Go project indelible already runs the canonical playbook on every
push and PR; this lift brings antd-go to that bar.
New workflow .github/workflows/go-ci.yml:
- `Lint` (every push/PR): go vet, go mod verify, golangci-lint
v1.64.8 — same toolchain version indelible pins to.
- `Test` (every push/PR): go test -count=1 -timeout 5m ./...
- `Race detection` (main-only): go test -race. Roughly doubles
runtime so it runs as a post-merge canary rather than a per-PR gate.
- `Security Scanning` (main-only, continue-on-error): govulncheck.
Advisory because govulncheck surfaces Go stdlib advisories that
require toolchain upgrades (not code changes) and hits external
registries — pattern lifted from indelible's ci.yml.
Cancel-in-flight + concurrency settings mirror indelible: PR pushes
cancel prior in-flight PR runs; main pushes never cancel.
Fixes the eight lint hits the first golangci-lint pass surfaces:
- `client_test.go`: 29 unchecked `json.NewEncoder(w).Encode(...)`
call sites in the mock daemon. Introduces a `writeJSON` helper
that explicitly ignores the encode error and updates every call
site — cleaner than scattering `_ =` prefixes through the file.
(The realistic failure mode is the client side dropping the
connection mid-response; surfaces as the read-side test failing
rather than the write-side.)
- `discover_test.go`: macOS branch was the only path in
`withTempPortFile` not wrapping `os.MkdirAll` / `os.WriteFile`
in `if err != nil { t.Fatal(err) }`. Matches the other branches.
- `discover_windows.go`: `proc.Release()` return value now
explicitly discarded with `_ =` — release failure is non-fatal
for the "process exists" check.
- `grpc_client_test.go`: two `if err := s.Serve(lis); err != nil {}`
empty-branch blocks (SA9003) replaced with deliberate-ignore
`_ = s.Serve(lis)` + clarifying comment.
Verified locally on Go 1.25.6 / golangci-lint v1.64.8:
- `go vet ./...` clean
- `go mod verify`: all modules verified
- `golangci-lint run ./...` clean
- `go test ./...`: PASS
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Mirrors the negation-in-paths fix used in ci.yml. GitHub Actions only allows EITHER `paths` OR `paths-ignore` on a trigger, not both — combining them silently rejects the workflow with a "workflow file issue" 0s failure. Use a negation pattern inside `paths` instead. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Nic-dorman
force-pushed
the
nic/v2-339-antd-go-ci
branch
from
May 20, 2026 11:18
af6ea7a to
45ad96e
Compare
Nic-dorman
added a commit
that referenced
this pull request
May 21, 2026
Cuts v0.8.0 atop v0.7.1. Substantial breaking-change roll-up of the put/get rename, the private-file PUT/GET gap close, and several minor surface cleanups -- bundled here so the v1.0 cut can ship stable on top. ## Breaking (antd daemon) - feat(antd)!: bind to 127.0.0.1 by default on REST and gRPC (#107). Previously bound 0.0.0.0; use --bind-rest / --bind-grpc to override. - chore: remove dead graph_entry surface from antd proto + 5 SDKs (#92). GraphService and its 4 RPCs are gone; REST mounts dropped. - chore: remove dir_upload_public / dir_download_public surface (#95). Use file_put_public on a directory path instead; the daemon recurses. - feat(antd)!: normalize put/get convention + close private-file PUT and GET gaps (#115). Method renames across proto + REST + SDKs: data_put_private -> data_put data_get_private -> data_get file_upload_public -> file_put_public file_download_public -> file_get_public New: file_put / file_get for the private file path (previously only the public variant existed). New typed results: DataPutResult, DataPutPublicResult, FilePutResult, FilePutPublicResult; PutResult is now annotated as chunk_put only. ## Additive - feat(antd): honor payment_mode on gRPC put/cost paths and REST cost endpoints (#114). Optional kwarg threaded through every put/cost signature; empty/omitted maps to "auto" so older clients keep working. - feat: external-signer public uploads + single-chunk prepare/finalize across 15 SDKs (#90). - docs+spec: openapi.yaml refreshed for the v1.0 surface, including POST /v1/chunks/prepare and /v1/chunks/finalize for single-chunk external-signer publish (#126). ## SDK fan-out (PaymentMode + put/get convention, all 15) #116 antd-go, #117 antd-py/ruby/elixir, #118 antd-rust, #119 antd-csharp, #120 antd-java, #121 antd-swift, #122 antd-dart, #123 antd-kotlin, #124 antd-cpp, #125 antd-js/php/zig/lua, #127 antd-mcp. ## SDK example + build fixes - fix(antd-go): make 03-files example self-contained and runnable (#91) - fix(examples): make 04-files runnable across cpp/rust/elixir/lua/php/ruby/zig (#93) - fix(examples): runnable dart 04_files + java Example03Files; add java Example03Chunks (#94) - feat: gRPC transport example for antd-py and antd-rust (#113) - feat(antd-py): 07_external_signer example + ant-dev dispatcher entry (#98) - feat(antd-js): 07-external-signer example + antd-py empty-payments fix (#99) - feat(rust/go): 07-external-signer examples (#100) - feat(antd-csharp): 07_external_signer example (#101) - feat(antd-java): 07_external_signer example (#102) - feat(antd-kotlin): 07_external_signer example (#103) - feat(antd-dart): 07_external_signer example (#104) - feat(antd-ruby): 07_external_signer example (#105) - feat(antd-php): 07_external_signer example (#106) - chore(antd-kotlin): drop stale GraphDescendant from local proto copy (#108) ## Docs / infra - docs: external-signer flow reference + ABI + python smoke test (#97) - docs: add SECURITY.md with threat model and disclosure policy (#109) - docs!: refresh per-SDK READMEs + llms-full.txt + openapi.yaml for v1.0 surface (#126) - ci: add Go lint + test + vuln scanning for antd-go (#112) - ci: extend antd-rust to sibling-repo parity (fmt + clippy + audit + doc) (#111) - ci: skip antd/openapi.yaml and llms-full.txt from triggering CI (#128) - chore(scripts): add full-stack + integration sweep helpers (#96) - fix(antd-rust): regenerate Cargo.lock to unbreak --locked CI (#110) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
antd-go ships as a v1.0 SDK but has had no CI coverage at all — the existing
ci.ymlpath filter isantd/**,antd-rust/**,.github/workflows/ci.ymland skips antd-go entirely. Sibling Go project indelible already runs the canonical Go toolchain on every push/PR; this PR lifts that playbook over to antd-go.New workflow:
.github/workflows/go-ci.ymlgo vet,go mod verify,golangci-lint v1.64.8(same version indelible pins to)go test -count=1 -timeout 5m ./...mainpush onlygo test -race. Roughly doubles runtime so it runs as a post-merge canary rather than a per-PR gate.mainpush only,continue-on-error: truegovulncheck ./.... Advisory because govulncheck surfaces Go stdlib advisories that require toolchain upgrades (not code changes) and hits external registries — pattern lifted from indelible's ci.yml.Concurrency settings mirror indelible: PR pushes cancel prior in-flight PR runs; main pushes never cancel.
Lint fixes (first golangci-lint pass)
The first run surfaced 8 hits, all mechanical:
client_test.go× 29 — uncheckedjson.NewEncoder(w).Encode(...)in the mock daemon. Introduced awriteJSONhelper that explicitly ignores the encode error and updated every call site (cleaner than scattering_ =prefixes). Realistic failure mode is the client dropping connection mid-response, which surfaces on the read side anyway.discover_test.go— macOS branch ofwithTempPortFilewas the only one not wrappingos.MkdirAll/os.WriteFileinif err != nil { t.Fatal(err) }. Now matches the windows/linux branches.discover_windows.go—proc.Release()return value explicitly discarded with_ =. Release failure is non-fatal for the "process exists" check.grpc_client_test.go× 2 —if err := s.Serve(lis); err != nil {}empty-branch blocks (SA9003). Replaced with deliberate-ignore_ = s.Serve(lis)+ clarifying comment.Test plan
go vet ./...clean inantd-go/go mod verify: all modules verifiedgolangci-lint run ./...clean (v1.64.8)go test ./...: PASS (~1.4s)Lint+Testjobs green;Race detectionandSecurity Scanningnot triggered until merged to mainNotes
golangci-lintandgovulncheckare now in/c/Users/nbdor/go/bin/locally. Will also install both on dev2 before this merges — see feedback memory: mirror CI tools onto dev2.