spf13/cobraApache-2.0adbc881Report / request removal

CI, Linting & Release Automation

Cobra uses GitHub Actions to run license-header checks, Go linting, and cross-platform tests on repository changes, including pull requests.

Repository automation also labels pull requests from changed-file patterns and schedules weekly dependency updates for Go modules and GitHub Actions.

Sources: .github/labeler.yml:1-24, .github/dependabot.yml:1-12

Core concepts

Test workflow

The test workflow is configured to run on pushes, pull requests, and manual dispatches.

Sources: .github/workflows/test.yml:3-6

License-header check

The lic-headers job checks repository files with addlicense, while excluding .github/**.

Sources: .github/workflows/test.yml:17-32

Lint job

The golangci-lint job sets up Go from the ^1.22 release line and runs golangci/golangci-lint-action@v8.0.0 with the latest linter version.

Sources: .github/workflows/test.yml:35-54

Unix test matrix

The test-unix job runs on Ubuntu and macOS for Go 1.17.x through Go 1.24.x.

Sources: .github/workflows/test.yml:56-86

Windows test job

The test-win job runs on Windows through an MSYS2 MINGW64 shell and installs Git, Make, Unzip, and Go.

Sources: .github/workflows/test.yml:96-117

Linter configuration

The .golangci.yml configuration sets the run timeout, enables formatters, selects linters, and defines exclusions and govet settings.

Sources: .golangci.yml:15-24, .golangci.yml:25-81

Path-based labeler

The labeler configuration maps changed-file globs to area labels.

Sources: .github/labeler.yml:1-24

Dependabot updates

Dependabot has separate weekly update configurations for the Go module ecosystem and GitHub Actions.

Sources: .github/dependabot.yml:1-12

What checks run automatically

The workflow is triggered by push, pull_request, and workflow_dispatch; it also grants read access to repository contents. A pull request therefore enters the same workflow definition that can also run for pushes or manual dispatches.

The visible jobs cover license headers, linting, Unix testing, and Windows testing.

JobEnvironmentMain operation
lic-headersubuntu-latestRuns addlicense with -check and ignores .github/**.
golangci-lintubuntu-latestSets up Go and runs the latest golangci-lint action.
test-unixUbuntu and macOSRuns make richtest across the Go-version matrix.
test-winwindows-latest, MSYS2 MINGW64Installs Windows-side tooling and runs make richtest.

The four jobs are declared under the workflow’s jobs block, with separate setup and execution steps for each environment.

The Unix matrix contains Go versions 1.17.x, 1.18.x, 1.19.x, 1.20.x, 1.21.x, 1.22.x, 1.23.x, and 1.24.x, on both Ubuntu and macOS. The setup step converts each matrix value into the corresponding 1.${{ matrix.go }}.x version.

On macOS, versions below Go 1.24 set GO_TEST_FLAGS to -ldflags=-linkmode=external; the workflow comments explain that this forces external linking for those runner environments.

The lint job is not part of the Unix version matrix: it separately requests Go ^1.22, enables check-latest, enables caching, and invokes the linter action with version: latest and args: --verbose.

The Windows job uses an MSYS2 setup with msystem: MINGW64, updates the environment, installs git, make, unzip, and mingw-w64-x86_64-go, then runs make richtest.

This diagram shows how the workflow trigger fans out to the four visible check jobs.

Automated CI checks — Which checks run when a pull request enters the workflow?

Evidence

Sources: .github/workflows/test.yml:3-12, .github/workflows/test.yml:3-6, .github/workflows/test.yml:35-54, .github/workflows/test.yml:56-94, .github/workflows/test.yml:96-130, .github/workflows/test.yml:56-73, .github/workflows/test.yml:81-86, .github/workflows/test.yml:72-78

What linting enforces

The configuration runs for up to five minutes and enables both gofmt and goimports as formatters. It sets default: none, so the active lint policy is the explicitly listed enable set rather than the default linter collection.

LinterContributor-visible concern
errcheckUnchecked errors.
goconstRepeated constants or strings.
gocriticCode patterns identified by gocritic.
gosecSecurity-related findings.
govetVet-detectable correctness issues.
ineffassignIneffective assignments.
misspellMisspelled words.
nolintlintProblems with lint suppression directives.
staticcheckStatic-analysis findings.
unconvertUnnecessary conversions.
unusedUnused code.

These are the linters currently enabled; other names in the same section are commented out and therefore are not listed as active by this configuration.

The exclusions apply presets for common-false-positives, legacy, and std-error-handling, and set warn-unused: true so unused exclusion rules are reported.

For test files, goconst is excluded, and the configuration also excludes goconst findings for the strings true, bash, zsh, fish, and powershell. Test files may also contain an unused //nolint:staticcheck directive without triggering nolintlint under the specified exclusion.

The govet settings disable the buildtag check because the configuration allows both build-tag syntaxes for Go 1.15 compatibility.

Sources: .golangci.yml:17-24, .golangci.yml:25-54, .golangci.yml:55-60, .golangci.yml:61-68, .golangci.yml:69-74, .golangci.yml:75-81

How labels and dependency updates are maintained

The labeler workflow runs on pull_request_target, uses actions/labeler@v5, and grants the action pull-requests: write permission so it can add labels.

The labeler configuration evaluates changed files with any-glob-to-any-file rules.

LabelMatching path
area/docs-generationFiles under doc/**.
area/cobra-command./cobra.go, ./cobra_test.go, or ./*command*.go.
area/flagsFiles matching ./args*.go.
area/githubFiles under .github/**.
area/shell-completionFiles matching ./*completions*.

A new pull request can receive each matching area label when its changed files satisfy the corresponding glob rule.

Dependabot checks the Go module ecosystem from / weekly and separately checks GitHub Actions from / weekly. Both update streams set open-pull-requests-limit: 99.

Sources: .github/workflows/labeler.yml:1-18, .github/labeler.yml:1-24, .github/dependabot.yml:1-12

How it connects

The CI workflow reads repository-level automation files rather than Cobra’s command execution code: its lint job invokes golangci-lint, while the labeler action uses the path rules in .github/labeler.yml.

For local build, test, and submission guidance, use Repository Layout & Development Setup. The workflow’s Unix and Windows jobs both culminate in make richtest, while their runners and setup steps provide the surrounding platform coverage.

For how Cobra’s tests exercise library behavior, see Testing Patterns. The automated checks described here provide the repository-level execution environments in which those tests run.

Sources: .github/workflows/test.yml:35-54, .github/labeler.yml:1-24, .github/workflows/test.yml:56-94, .github/workflows/test.yml:96-130

Key takeaways

  • Pull requests trigger license, lint, Unix matrix, and Windows checks.
  • Unix tests cover Go 1.17.x through Go 1.24.x on Ubuntu and macOS.
  • The linter uses gofmt, goimports, and the explicitly enabled linters in .golangci.yml.
  • Labels are selected from changed-file glob rules.
  • Dependabot updates Go modules and GitHub Actions weekly.

Want this for your repos?

Try Angada AI Wiki