Atlas / Skills / samber / Golang Continuous Integration

Golang Continuous IntegrationCAUTION

skills/samber/golang-continuous-integration

๐Ÿง‘๐ŸŽจ A collection of Golang agentic skills that works

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.4.2
Hosts
4 documented
License
MIT
Stars
3,420
01

Overview

๐Ÿง‘๐ŸŽจ A collection of Golang agentic skills that works

Read from source at commit 3823d8ae0038OBSERVED ยท 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

npx skills add https://github.com/samber/cc-skills-golang --agent github-copilot --skill '*' -y --copy
npx skills add https://github.com/samber/cc-skills-golang --agent github-copilot --skill '*' -y --copy
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: golang-continuous-integration
description: "GitHub Actions CI/CD pipeline configuration for Golang projects โ€” workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release pipelines, Docker build/push, repository security settings, and AI-driven PR review. Use when setting up or improving Go project CI, writing or fixing `.github/workflows/*.yml`, adding a linter or security scanner as a pipeline job, wiring automated dependency-update bots, or adding quality gates. Covers wiring tools into a pipeline, not the analysis they perform: do NOT use for choosing or interpreting security findings (โ†’ See `samber/cc-skills-golang@golang-security` skill) or for choosing, upgrading, or auditing dependency versions (โ†’ See `samber/cc-skills-golang@golang-dependency-management` skill)."
user-invocable: true
license: MIT
compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang.
metadata:
  author: samber
  version: "1.4.2"
  openclaw:
    emoji: "๐Ÿš€"
    homepage: https://github.com/samber/cc-skills-golang
    requires:
      bins:
        - go
        - goreleaser
        - gh
    install:
      - kind: brew
        formula: goreleaser
        bins: [goreleaser]
      - kind: brew
        formula: gh
        bins: [gh]
      - kind: npm
        package: skills
        bins: [skills]
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch Bash(goreleaser:*) Bash(gh:*) AskUserQuestion
---

**Persona:** You are a Go DevOps engineer. You treat CI as a quality gate โ€” every pipeline decision is weighed against build speed, signal reliability, and security posture.

**Modes:**

- **Setup** โ€” adding CI to a project for the first time: start with the Quick Reference table, then generate workflows in this order: test โ†’ lint โ†’ security โ†’ release. Prefer the latest stable major version for each GitHub Action.
- **Improve** โ€” auditing or extending an existing pipeline: read current workflow files first, identify gaps against the Quick Reference table, then propose targeted additions without duplicating existing steps.

**Dependencies:**

- goreleaser: `go install github.com/goreleaser/goreleaser/v2@latest`
- gh: `brew install gh`

# Go Continuous Integration

Set up production-grade CI/CD pipelines for Go projects using GitHub Actions.

## Action Versions

The versions in the examples below are reference versions that may be outdated. GitHub Actions release frequently โ€” the current major version for each action (`actions/checkout`, `actions/setup-go`, `golangci/golangci-lint-action`, `codecov/codecov-action`, `goreleaser/goreleaser-action`, etc.) may differ from what is shown here.

## Quick Reference

| Stage         | Tool                        | Purpose                       |
| ------------- | --------------------------- | ----------------------------- |
| **Test**      | `go test -race`             | Unit + race detection         |
| **Coverage**  | `codecov/codecov-action`    | Coverage reporting            |
| **Lint**      | `golangci-lint`             | Comprehensive linting         |
| **Vet**       | `go vet`                    | Built-in static analysis      |
| **SAST**      | `gosec`, `CodeQL`, `Bearer` | Security static analysis      |
| **Vuln scan** | `govulncheck`               | Known vulnerability detection |
| **Docker**    | `docker/build-push-action`  | Multi-platform image builds   |
| **Deps**      | Dependabot / Renovate       | Automated dependency updates  |
| **Release**   | GoReleaser                  | Automated binary releases     |
| **AI Review** | Claude Code / Copilot       | AI-powered PR review          |

---

## Testing

`.github/workflows/test.yml` โ€” see [test.yml](./assets/test.yml)

Adapt the Go version matrix to match `go.mod`:

```
go 1.23   โ†’ matrix: ["1.23", "1.24", "1.25", "1.26", "1.27", "stable"]
go 1.24   โ†’ matrix: ["1.24", "1.25", "1.26", "1.27", "stable"]
go 1.25   โ†’ matrix: ["1.25", "1.26", "1.27", "stable"]
go 1.26   โ†’ matrix: ["1.26", "1.27", "stable"]
go 1.27   โ†’ matrix: ["1.27", "stable"]
```

Use `fail-fast: false` so a failure on one Go version doesn't cancel the others.

Go 1.27 raises the Darwin floor to macOS 13 (Ventura). `macos-latest`/`macos-14`+ runners are unaffected; only pin an older `macos-12` runner if a project still needs it, and note it can no longer build with a Go 1.27 toolchain.

Test flags:

- `-race`: CI MUST run tests with the `-race` flag (catches data races โ€” undefined behavior in Go)
- `-shuffle=on`: Randomize test order to catch inter-test dependencies
- `-coverprofile`: Generate coverage data
- `git diff --exit-code`: Fails if `go mod tidy` changes anything

### Coverage Configuration

CI SHOULD enforce code coverage thresholds. Configure thresholds in `codecov.yml` at the repo root โ€” see [codecov.yml](./assets/codecov.yml)

---

## Integration Tests

`.github/workflows/integration.yml` โ€” see [integration.yml](./assets/integration.yml)

Use `-count=1` to disable test caching โ€” cached results can hide flaky service interactions.

---

## Linting

`golangci-lint` MUST be run in CI on every PR. `.github/workflows/lint.yml` โ€” see [lint.yml](./assets/lint.yml)

### golangci-lint Configuration

Create `.golangci.yml` at the root of the project. See the `samber/cc-skills-golang@golang-lint` skill for the recommended configuration.

---

## Security & SAST

`.github/workflows/security.yml` โ€” see [security.yml](./assets/security.yml)

CI MUST run `govulncheck` โ€” it only reports vulnerabilities in code paths your project actually calls, unlike generic CVE scanners.

- CodeQL results appear in the repository's Security tab.
- Bearer is good at detecting sensitive data flow issues.

### CodeQL Configuration

Create `.github/codeql/codeql-config.yml` to use the extended security query suite โ€” see [codeql-config.yml](./assets/codeql-config.yml)

Available query suites:

- **default
05

Trust audit

CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (4)

HIGHHard-coded secrets ยท secret.db_uri ยท CWE-798, CWE-321
assets/integration.yml:52
DATABASE_URL: postgres://test:test@localhost:5432/testdb?sslmode=disable
LOWPrompt injection ยท prompt.authority_framing ยท CWE-94, CWE-1427
SKILL.md:154
> **Security warning:** This workflow requires `contents: write` and `pull-requests: write` โ€” these are elevated permissions that allow merging PRs and modifying repository content. The `if: github.ac
LOWPrompt injection ยท prompt.authority_framing ยท CWE-94, CWE-1427
assets/copilot-review-instructions.md:10
You are a senior Go engineer reviewing a pull request. Review the diff thoroughly and provide actionable, prioritized feedback.
LOWPrompt injection ยท prompt.authority_framing ยท CWE-94, CWE-1427
references/repo-security.md:33
This means workflows start with no write access by default. Each workflow that needs elevated permissions must explicitly declare them in its `permissions:` block. This is defense-in-depth: if a workf

Gates applied: no_behavioural_pass.

Audited 2026-10-08 ยท audit v0.4.1 ยท source sha 3823d8ae0038full audit observations/trust-audit/skill/samber__golang-continuous-integration.json ยท Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-083823d8ae0038CAUTIONB89first audit
07

Questions

What does the Golang Continuous Integration skill do?

๐Ÿง‘๐ŸŽจ A collection of Golang agentic skills that works

Is Golang Continuous Integration safe to install?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Golang Continuous Integration access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Golang Continuous Integration work with?

Its documentation mentions claude-code, codex, copilot and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (3823d8ae0038), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement