Skip to content

Commit 6bee483

Browse files
fix(ci): install golangci-lint via go install instead of the prebuilt release binary
1 parent 586c14e commit 6bee483

2 files changed

Lines changed: 24 additions & 4 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,15 @@ jobs:
6060
run: make ui-react
6161

6262
- name: Install golangci-lint
63+
# `go install` (not the release install.sh + prebuilt binary) so the
64+
# linter is always built with the SAME Go toolchain this job just set
65+
# up — golangci-lint refuses to run when built with an older Go than
66+
# the module it's targeting, so a prebuilt binary silently breaks
67+
# every time the pinned toolchain in go.mod moves past it. install.sh
68+
# also matched the wrong release asset for v2.13.1 (grabbed the
69+
# .sbom.json instead of the tarball) and failed checksum verification.
6370
run: |
64-
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b "$(go env GOPATH)/bin" v2.13.1
71+
go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.13.1
6572
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
6673
6774
- name: make check (fmt, vet, lint, unit+race tests, web lint+build)
@@ -161,8 +168,15 @@ jobs:
161168
run: make ui-react
162169

163170
- name: Install golangci-lint
171+
# `go install` (not the release install.sh + prebuilt binary) so the
172+
# linter is always built with the SAME Go toolchain this job just set
173+
# up — golangci-lint refuses to run when built with an older Go than
174+
# the module it's targeting, so a prebuilt binary silently breaks
175+
# every time the pinned toolchain in go.mod moves past it. install.sh
176+
# also matched the wrong release asset for v2.13.1 (grabbed the
177+
# .sbom.json instead of the tarball) and failed checksum verification.
164178
run: |
165-
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b "$(go env GOPATH)/bin" v2.13.1
179+
go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.13.1
166180
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
167181
168182
- name: Run pre-commit

‎.github/workflows/release.yml‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -75,10 +75,16 @@ jobs:
7575
run: make web-deps
7676

7777
- name: Install golangci-lint
78+
# `go install` (not the release install.sh + prebuilt binary) so the
79+
# linter is always built with the SAME Go toolchain this job just set
80+
# up — golangci-lint refuses to run when built with an older Go than
81+
# the module it's targeting, so a prebuilt binary silently breaks
82+
# every time the pinned toolchain in go.mod moves past it. install.sh
83+
# also matched the wrong release asset for v2.13.1 (grabbed the
84+
# .sbom.json instead of the tarball) and failed checksum verification.
7885
run: |
7986
set -euo pipefail
80-
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh \
81-
| sh -s -- -b "$(go env GOPATH)/bin" "${GOLANGCI_LINT_VERSION}"
87+
go install "github.com/golangci/golangci-lint/v2/cmd/golangci-lint@${GOLANGCI_LINT_VERSION}"
8288
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
8389
8490
# ORDER IS LOAD-BEARING. `make ui-react` builds web/ and syncs web/dist into

0 commit comments

Comments
 (0)