Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

ci: add go test, go vet, and staticcheck gates to the build-verify workflow

未关闭
#355 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

@Harishrs2006 已经在做这个了。

开始于 2026年5月9日。

  • #356 来自 @Harishrs2006 —— 未关闭

评估

难度
3/5
预计耗时
1-2 天
新手友好度
74/100
Issue 类型
功能
描述清晰度
描述清楚
活跃度
冷清
技术栈
github-actions, go

调研方向

从 .github/workflows/build-verify.yml 和现有的 Build Go packages 步骤开始,然后检查 Makefile 并在本地运行提议的 Go 检查。完成意味着 workflow 在 pushes 和 pull requests 上运行 go test ./...、go vet ./... 和 staticcheck,具有相应的 make test 和 make vet targets,并且所有现有测试都通过。

由索引模型根据 Issue 内容生成。

描述

Reason/Context

The current build-verify.yml CI workflow only compiles binaries — it never runs tests, go vet, or any static analysis. This means bugs ship silently and contributors get no automated feedback on correctness.

Proof from the current open PR queue — every one of these bugs existed in master and CI never caught them:

  1. req.Body read instead of resp.Body in DownloadArtifact → PR #338 (go vet catches this)
  2. panic(err.Error()) in connector code → PR #341, #319 (staticcheck catches this)
  3. TestDeleteContext fails on every clean checkout → PR #334 (go test ./... catches this)
  4. OAuth2 tokens printed unconditionally to stderr → PR #345 (caught by tests with log capture)
  5. String-concatenation JSON injection risk → PR #341 (staticcheck catches this)

The motivation: CI should be the first line of defence. Right now it is not.

Description

Add three mandatory quality gates to build-verify.yml that run on every PR and push:

  1. go test ./... — runs the existing unit test suite (currently never executed in CI)
  2. go vet ./... — Go's built-in analyser, catches real bugs like wrong body reads, bad panic arguments, printf mismatches
  3. staticcheck — industry-standard linter, zero config, no false positives

Also add make test and make vet targets to Makefile so contributors can run the same checks locally before pushing.

This is not a breaking change — it only adds new CI steps. If existing tests are currently failing on master,
those failures will need to be fixed as part of this PR.

Implementation ideas

Add before the existing Build Go packages step in .github/workflows/build-verify.yml:

- name: Run unit tests
  run: go test ./...

- name: Run go vet
  run: go vet ./...

- name: Run staticcheck
  uses: dominikh/staticcheck-action@v1
  with:
    version: latest
    install-go: false


`staticcheck` is preferred over `golangci-lint` — zero config, no false positives, directly catches the bug classes above.

Add to `Makefile`:

```makefile
.PHONY: test
test:
	go test ./...

.PHONY: vet
vet:
	go vet ./...
主要语言
Go
星标
57
派生
73
平均合并
1 天 8 小时
30 天内合并 PR
29

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

microcks/microcks-cli 的其他 Issue

查看 microcks/microcks-cli 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。