diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8a0f079..cdb2a3b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -35,15 +35,23 @@ jobs: - name: Test run: go test ./... + - name: Install govulncheck + run: go install golang.org/x/vuln/cmd/govulncheck@latest + + - name: Vulnerability check + run: govulncheck ./... + - name: Install swag run: go install github.com/swaggo/swag/cmd/swag@latest - name: Swagger docs up to date run: | + cp docs/swagger.json docs/swagger.json.bak swag init -g cmd/beacon/main.go -o docs --parseInternal --parseDependency - if [ -n "$(git diff --name-only docs/)" ]; then + if ! diff -q docs/swagger.json docs/swagger.json.bak > /dev/null; then echo "Swagger docs are out of date. Run swag init and commit the result." - git diff --name-only docs/ + rm docs/swagger.json.bak exit 1 fi + rm docs/swagger.json.bak diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..a45259d --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,39 @@ +# Copyright 2026 Beacon Contributors +# SPDX-License-Identifier: AGPL-3.0-or-later +name: CodeQL + +on: + push: + branches: [main, dev] + pull_request: + schedule: + - cron: '0 8 * * 1' # every Monday at 08:00 UTC + +jobs: + analyze: + if: false # remove after public release and enabled on repo + name: Analyze + runs-on: ubuntu-latest + permissions: + actions: read + contents: read + security-events: write + + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-go@v5 + with: + go-version-file: go.mod + cache: true + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: go + + - name: Build + run: go build ./... + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 diff --git a/README.md b/README.md index c09d469..2d17f2e 100644 --- a/README.md +++ b/README.md @@ -4,6 +4,7 @@ MeshCore Beacon is a MeshCore network observation backend. It connects to one or more MeshCore MQTT brokers, ingests LoRa packet traffic in real time, stores it in PostgreSQL, and streams live events to WebSocket clients. +[![CodeQL](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/codeql.yml/badge.svg)](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/codeql.yml) [![CI](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/ci.yml/badge.svg)](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/ci.yml) [![Docker](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/docker-publish.yml/badge.svg)](https://github.com/MeshCore-Beacon/beacon-server/actions/workflows/docker-publish.yml) diff --git a/go.mod b/go.mod index 5659a03..5fbfc0c 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/MeshCore-Beacon/beacon-server -go 1.26.1 +go 1.26.4 require ( github.com/coder/websocket v1.8.14