Golang Continuous IntegrationCAUTION
๐ง๐จ A collection of Golang agentic skills that works
Overview
๐ง๐จ A collection of Golang agentic skills that works
3823d8ae0038OBSERVED ยท 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npx skills add https://github.com/samber/cc-skills-golang --agent github-copilot --skill '*' -y --copy
npx skills add https://github.com/samber/cc-skills-golang --agent github-copilot --skill '*' -y --copy
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit โ this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: golang-continuous-integration
description: "GitHub Actions CI/CD pipeline configuration for Golang projects โ workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release pipelines, Docker build/push, repository security settings, and AI-driven PR review. Use when setting up or improving Go project CI, writing or fixing `.github/workflows/*.yml`, adding a linter or security scanner as a pipeline job, wiring automated dependency-update bots, or adding quality gates. Covers wiring tools into a pipeline, not the analysis they perform: do NOT use for choosing or interpreting security findings (โ See `samber/cc-skills-golang@golang-security` skill) or for choosing, upgrading, or auditing dependency versions (โ See `samber/cc-skills-golang@golang-dependency-management` skill)."
user-invocable: true
license: MIT
compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang.
metadata:
author: samber
version: "1.4.2"
openclaw:
emoji: "๐"
homepage: https://github.com/samber/cc-skills-golang
requires:
bins:
- go
- goreleaser
- gh
install:
- kind: brew
formula: goreleaser
bins: [goreleaser]
- kind: brew
formula: gh
bins: [gh]
- kind: npm
package: skills
bins: [skills]
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch Bash(goreleaser:*) Bash(gh:*) AskUserQuestion
---
**Persona:** You are a Go DevOps engineer. You treat CI as a quality gate โ every pipeline decision is weighed against build speed, signal reliability, and security posture.
**Modes:**
- **Setup** โ adding CI to a project for the first time: start with the Quick Reference table, then generate workflows in this order: test โ lint โ security โ release. Prefer the latest stable major version for each GitHub Action.
- **Improve** โ auditing or extending an existing pipeline: read current workflow files first, identify gaps against the Quick Reference table, then propose targeted additions without duplicating existing steps.
**Dependencies:**
- goreleaser: `go install github.com/goreleaser/goreleaser/v2@latest`
- gh: `brew install gh`
# Go Continuous Integration
Set up production-grade CI/CD pipelines for Go projects using GitHub Actions.
## Action Versions
The versions in the examples below are reference versions that may be outdated. GitHub Actions release frequently โ the current major version for each action (`actions/checkout`, `actions/setup-go`, `golangci/golangci-lint-action`, `codecov/codecov-action`, `goreleaser/goreleaser-action`, etc.) may differ from what is shown here.
## Quick Reference
| Stage | Tool | Purpose |
| ------------- | --------------------------- | ----------------------------- |
| **Test** | `go test -race` | Unit + race detection |
| **Coverage** | `codecov/codecov-action` | Coverage reporting |
| **Lint** | `golangci-lint` | Comprehensive linting |
| **Vet** | `go vet` | Built-in static analysis |
| **SAST** | `gosec`, `CodeQL`, `Bearer` | Security static analysis |
| **Vuln scan** | `govulncheck` | Known vulnerability detection |
| **Docker** | `docker/build-push-action` | Multi-platform image builds |
| **Deps** | Dependabot / Renovate | Automated dependency updates |
| **Release** | GoReleaser | Automated binary releases |
| **AI Review** | Claude Code / Copilot | AI-powered PR review |
---
## Testing
`.github/workflows/test.yml` โ see [test.yml](./assets/test.yml)
Adapt the Go version matrix to match `go.mod`:
```
go 1.23 โ matrix: ["1.23", "1.24", "1.25", "1.26", "1.27", "stable"]
go 1.24 โ matrix: ["1.24", "1.25", "1.26", "1.27", "stable"]
go 1.25 โ matrix: ["1.25", "1.26", "1.27", "stable"]
go 1.26 โ matrix: ["1.26", "1.27", "stable"]
go 1.27 โ matrix: ["1.27", "stable"]
```
Use `fail-fast: false` so a failure on one Go version doesn't cancel the others.
Go 1.27 raises the Darwin floor to macOS 13 (Ventura). `macos-latest`/`macos-14`+ runners are unaffected; only pin an older `macos-12` runner if a project still needs it, and note it can no longer build with a Go 1.27 toolchain.
Test flags:
- `-race`: CI MUST run tests with the `-race` flag (catches data races โ undefined behavior in Go)
- `-shuffle=on`: Randomize test order to catch inter-test dependencies
- `-coverprofile`: Generate coverage data
- `git diff --exit-code`: Fails if `go mod tidy` changes anything
### Coverage Configuration
CI SHOULD enforce code coverage thresholds. Configure thresholds in `codecov.yml` at the repo root โ see [codecov.yml](./assets/codecov.yml)
---
## Integration Tests
`.github/workflows/integration.yml` โ see [integration.yml](./assets/integration.yml)
Use `-count=1` to disable test caching โ cached results can hide flaky service interactions.
---
## Linting
`golangci-lint` MUST be run in CI on every PR. `.github/workflows/lint.yml` โ see [lint.yml](./assets/lint.yml)
### golangci-lint Configuration
Create `.golangci.yml` at the root of the project. See the `samber/cc-skills-golang@golang-lint` skill for the recommended configuration.
---
## Security & SAST
`.github/workflows/security.yml` โ see [security.yml](./assets/security.yml)
CI MUST run `govulncheck` โ it only reports vulnerabilities in code paths your project actually calls, unlike generic CVE scanners.
- CodeQL results appear in the repository's Security tab.
- Bearer is good at detecting sensitive data flow issues.
### CodeQL Configuration
Create `.github/codeql/codeql-config.yml` to use the extended security query suite โ see [codeql-config.yml](./assets/codeql-config.yml)
Available query suites:
- **defaultTrust audit
CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (4)
DATABASE_URL: postgres://test:test@localhost:5432/testdb?sslmode=disable
> **Security warning:** This workflow requires `contents: write` and `pull-requests: write` โ these are elevated permissions that allow merging PRs and modifying repository content. The `if: github.ac
You are a senior Go engineer reviewing a pull request. Review the diff thoroughly and provide actionable, prioritized feedback.
This means workflows start with no write access by default. Each workflow that needs elevated permissions must explicitly declare them in its `permissions:` block. This is defense-in-depth: if a workf
Gates applied: no_behavioural_pass.
3823d8ae0038full audit observations/trust-audit/skill/samber__golang-continuous-integration.json ยท Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3823d8ae0038 | CAUTION | B | 89 | first audit |
Questions
What does the Golang Continuous Integration skill do?
๐ง๐จ A collection of Golang agentic skills that works
Is Golang Continuous Integration safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Golang Continuous Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Golang Continuous Integration work with?
Its documentation mentions claude-code, codex, copilot and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (3823d8ae0038), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ this is the first audit.