Files
crypto/.github/workflows/ci.yml
T
Hanzo AI f1db74c283 ci: update actions to Node 24, fix golangci-lint v2 config
Update checkout@v5, setup-go@v6, cache@v5, codecov@v5. Pin
golangci-lint to v2.1.6 with version: "2" config. Fix release
workflow Go version to 1.26.1.
2025-12-27 12:07:55 -08:00

183 lines
4.3 KiB
YAML

name: CI
on:
push:
branches: [ main, master ]
pull_request:
branches: [ main, master ]
jobs:
test:
name: Test Post-Quantum Crypto
runs-on: ubuntu-latest
strategy:
matrix:
go-version: ['1.26.1']
cgo: ['0', '1']
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Set up Go
uses: actions/setup-go@v6
with:
go-version: ${{ matrix.go-version }}
- name: Cache Go modules
uses: actions/cache@v5
with:
path: ~/go/pkg/mod
key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-go-
- name: Install dependencies
run: |
go mod download
go mod tidy
- name: Format check
run: |
gofmt -s -l .
test -z "$(gofmt -s -l .)"
- name: Run ML-KEM tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing ML-KEM (FIPS 203) with CGO=${{ matrix.cgo }}"
go test -v ./mlkem/... -count=1 || true
- name: Run ML-DSA tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing ML-DSA (FIPS 204) with CGO=${{ matrix.cgo }}"
go test -v ./mldsa/... -count=1 || true
- name: Run SLH-DSA tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing SLH-DSA (FIPS 205) with CGO=${{ matrix.cgo }}"
go test -v ./slhdsa/... -count=1 || true
- name: Run Lamport tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing Lamport signatures with CGO=${{ matrix.cgo }}"
go test -v ./lamport/... -count=1 || true
- name: Run precompile tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing precompiled contracts with CGO=${{ matrix.cgo }}"
go test -v ./precompile/... -count=1 || true
- name: Run integration tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Running integration tests"
go test -v . -count=1 || true
- name: Run secret package tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing secret package (stub mode)"
go test -v ./secret/... -count=1
- name: Run encryption/HPKE tests
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Testing HPKE encryption (Go 1.26 stdlib)"
go test -v ./encryption/... -count=1
- name: Run benchmarks
if: matrix.cgo == '1'
env:
CGO_ENABLED: ${{ matrix.cgo }}
run: |
echo "Running performance benchmarks"
go test -bench=. -benchmem ./... || true
test-runtimesecret:
name: Test with GOEXPERIMENT=runtimesecret
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Set up Go
uses: actions/setup-go@v6
with:
go-version: '1.26.1'
- name: Build with runtimesecret
env:
GOEXPERIMENT: runtimesecret
CGO_ENABLED: '0'
run: go build ./...
- name: Test with runtimesecret
env:
GOEXPERIMENT: runtimesecret
CGO_ENABLED: '0'
run: go test -v -count=1 ./secret/... ./encryption/... .
security:
name: Security Scan
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Set up Go
uses: actions/setup-go@v6
with:
go-version: '1.26.1'
- name: Run Gosec Security Scanner
uses: securego/gosec@master
continue-on-error: true
with:
args: -exclude-dir=bn256 -exclude-dir=ipa/bandersnatch ./...
- name: Run Nancy vulnerability scanner
continue-on-error: true
run: |
go install github.com/sonatype-nexus-community/nancy@latest
go list -json -m all | nancy sleuth
build:
name: Build
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
go-version: ['1.26.1']
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Set up Go
uses: actions/setup-go@v6
with:
go-version: ${{ matrix.go-version }}
- name: Build
env:
CGO_ENABLED: '0'
run: make build
- name: Verify module
if: runner.os != 'Windows'
run: make verify