{"id":23914413,"url":"https://github.com/dlemel8/gophercon-2021-go-action","last_synced_at":"2026-06-09T21:32:05.889Z","repository":{"id":45560538,"uuid":"436319280","full_name":"dlemel8/gophercon-2021-go-action","owner":"dlemel8","description":null,"archived":false,"fork":false,"pushed_at":"2021-12-08T17:49:55.000Z","size":7,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-05-03T14:24:20.541Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dlemel8.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-12-08T16:38:35.000Z","updated_at":"2021-12-08T17:43:46.000Z","dependencies_parsed_at":"2023-01-04T18:32:43.864Z","dependency_job_id":null,"html_url":"https://github.com/dlemel8/gophercon-2021-go-action","commit_stats":{"total_commits":2,"total_committers":1,"mean_commits":2.0,"dds":0.0,"last_synced_commit":"143ed238b9f652f65ecd06f1ed05867b85b148da"},"previous_names":[],"tags_count":1,"template":false,"template_full_name":"the-gophers/go-action","purl":"pkg:github/dlemel8/gophercon-2021-go-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dlemel8%2Fgophercon-2021-go-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dlemel8%2Fgophercon-2021-go-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dlemel8%2Fgophercon-2021-go-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dlemel8%2Fgophercon-2021-go-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dlemel8","download_url":"https://codeload.github.com/dlemel8/gophercon-2021-go-action/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dlemel8%2Fgophercon-2021-go-action/sbom","scorecard":{"id":347072,"data":{"date":"2025-08-11","repo":{"name":"github.com/dlemel8/gophercon-2021-go-action","commit":"143ed238b9f652f65ecd06f1ed05867b85b148da"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.2,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/2 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/tweeter-automation.yaml:51","Info: jobLevel 'contents' permission set to 'read': .github/workflows/tweeter-automation.yaml:14","Info: jobLevel 'contents' permission set to 'read': .github/workflows/tweeter-automation.yaml:32","Info: jobLevel 'packages' permission set to 'read': .github/workflows/tweeter-automation.yaml:33","Warn: topLevel 'contents' permission set to 'write': .github/workflows/action-version.yaml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/image-release.yaml:7","Warn: topLevel 'packages' permission set to 'write': .github/workflows/image-release.yaml:8","Warn: no topLevel permission defined: .github/workflows/tweeter-automation.yaml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action-version.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/action-version.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/image-release.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/image-release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image-release.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/image-release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image-release.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/image-release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image-release.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/image-release.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tweeter-automation.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/dlemel8/gophercon-2021-go-action/tweeter-automation.yaml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:23: pin your Docker image by updating gcr.io/distroless/static:latest to gcr.io/distroless/static:latest@sha256:2e114d20aa6371fd271f854aa3d6b2b7d2e70e797bb3ea44fb677afec60db22c","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v1.0.0 not signed: https://api.github.com/repos/dlemel8/gophercon-2021-go-action/releases/54894063","Warn: release artifact v1.0.0 does not have provenance: https://api.github.com/repos/dlemel8/gophercon-2021-go-action/releases/54894063"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 2 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T07:20:02.742Z","repository_id":45560538,"created_at":"2025-08-18T07:20:02.742Z","updated_at":"2025-08-18T07:20:02.742Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34127343,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-09T02:00:06.510Z","response_time":63,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-01-05T10:13:42.226Z","updated_at":"2026-06-09T21:32:05.863Z","avatar_url":"https://github.com/dlemel8.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# GitHub Action Using Go\nThis is a starting point for a GitHub Action based in Go. This repo provides all the structure needed to build\na robust GitHub action using Go and following action development best practices.\n\n## Getting Started\nThis is a GitHub template repo, so when you click \"Use this template\", it will create a new copy of this\ntemplate in your org or personal repo of choice. Once you have created a repo from this template, you\nshould be able to clone and navigate to the root of the repository.\n\n### First Build\nFrom the root of your repo, you should be able to run the following to build and test the Go action.\n```shell script\ngo build ./...\ngo test ./...\n```\n\n### What's in Here?\n\n```\n.\n├── Dockerfile\n├── LICENSE\n├── README.md\n├── action.yaml\n├── go.mod\n├── go.sum\n├── main.go\n└── pkg\n    └── tweeter\n        ├── tweeter.go\n        └── tweeter_test.go\n```\n\n#### [action.yaml](./action.yaml)\nThe `action.yml` file contains the metadata which describes our action. This includes, but is not limited\nto the following.\n- name, description and author\n- inputs\n- outputs\n- branding\n- runs\n\nYou will see an example structure already exists. The example executes the Dockerfile and provides to it\nthe arguments described in the `runs` section. We map the sample input to the arguments of the Dockerfile.\n\nBy setting `runs.using: docker` we are telling the Actions runtime to execute the Dockerfile when the\nAction is used in a workflow.\n\nBy setting `runs.image: Dockerfile` we are telling the Actions runtime to build and then execute the\nDockerfile at the entrypoint defined in the Dockerfile. The build for the Dockerfile will happen\neach time the Action is executed, which can take a considerable amount of time depending on how long\nit takes to build your Go code. Later, we'll change this to a pre-built image for optimization. \n\n#### [Dockerfile](./Dockerfile)\nThis Dockerfile should look relatively familiar to folks who use containers to build Go code. We create a\nbuilder intermediate image based on Go 1.15.2, pull in the source, and build the application. After the\napplication has been built, the statically linked binary is copied into a thin image, which results in \nan image of roughly 8 MB.\n\n#### [go.mod](./go.mod) / [go.sum](./go.sum)\nGo module definition which will need to be updated with the name of your module.\n\n#### [main.go](./main.go)\nThis is the Go entrypoint for your GitHub Action. It is a simple command line application which can be\nexecuted outside the context of the Action by running the following. This is where you will add your Go code for your \nAction.\n\n#### [.github/workflows/tweeter-automation.yaml](.github/workflows/tweeter-automation.yaml)\nThis is the continuous integration / CLI release automation. The release workflow defined in this automation will\nis triggered by tags shaped like `v1.2.3`, and will create a GitHub release for a pushed tag. The release will \nuse the [./github/release.yml](.github/release.yml) to automatically generate structured release notes based on\npull request tags.\n\n#### [.github/workflows/action-version.yaml](./.github/workflows/action-version.yaml)\nThis action triggers when a new release is published. Upon publication of the new release, this will tag the repository\nwith the shortened major semantic version pointing at the highest semantic version within that major version. For \nexample, `v1.2.2` and `v1` point to the same ref `xyz`, a new tag is introduced `v1.2.3` which points to ref `abc`, this \naction will move the `v1` tag to point to `abc` rather than `xyz`. This enables consumers of an action to take a \n\"floating\" major semantic version dependency, like `my-action@v1`. \n\n#### [.github/workflows/image-release.yaml](./.github/workflows/image-release.yaml)\nThis action runs on tags shaped like `image-v1.2.3`, and will build and push a container image to the\nGitHub Container Registry.\n\nThis action is super useful for optimizing the execution time of your action. By pre-building the\nimage used in the Action, each invocation of your action can reference the image and not have to\nrebuild it for each invocation.\n\nOnce you push your first image you will also need to update the Container Registry to allow public access.\n\n## Lab Video\nTODO: record and post the first lab walking through creation, execution and optimization\n\n## Lab Instructions\n1) Click on \"Use this template\" on https://github.com/the-gophers/go-action, and create a repo of your own. I'm going \n   to call mine \"templated-action\", make it public, and click \"Create repository from template\".\n2) Clone your newly crated repo\n3) Run `go run . -h`.\n5) Run\n    ```shell script\n    $ go run . --dryRun --message hello\n    ::set-output name=sentMessage::hello\n    ```\n6) Checkout a new branch and let's make this our own GitHub Action. Run `git checkout -b my-action`\n7) Update `./action.yml` name, description, and author to something reasonable. The `name` field needs to be\n   unique to others in the store.\n8) When you are done with your changes, commit them, push your branch to GitHub, and open a pull request. In the PR,\n   you should see the CI action run and complete successfully. LGTM! Let's merge these changes. Click the\n   \"Merge pull request\" button, then delete the branch.\n9) Check out `main` and pull down the latest changes from GitHub (`git pull`).\n11) In `test-repo` click on Actions and run `test-action` with the inputs you desire. Navigate the UI to the running\n    action and see that it built the action, built the Dockerfile and executed the entrypoint Go application. Also note\n    how long it took to run the action. **Using a Dockerfile will cause it to rebuild that image EACH time the action\n    runs!**. We can do better than that. More ahead.\n12) Let's tag our first release (`git tag v1.0.0`) and push the tag\n    (`git push origin v1.0.0`). This should create our first release in GitHub via the `release action` workflow.\n13) Navigate to the `v1.0.0` release and click edit. Within the release edit page, you should see \"Publish this Action to the GitHub Marketplace\".\n    If you check that box, your action will now be publicly advertised to all of GitHub!\n14) **PSA:** The rest of this is optional. If you don't care about your action going fast, stop right here.\n15) Now we are going to make this **FAST** by pre-baking our container image. Go back to `templated-action` and edit\n    `./github/workflows/release-image.yml`. Change `docker.pkg.github.com/owner/` to use your repo owner for `owner`.\n    Commit and push the changes.\n17) Now tag the repo with `git tag image-v1.0.0` and then push the tag `git push origin image-v1.0.0`. This will\n    kick off the image release build.\n18) Replace `image: Dockerfile` with `image: docker://ghcr.io/your-repo/your-image:1.0.0` replacing the repo and image name.\n    Commit the changes and tag a new release of the Action as done in #12.\n19) Rerun the continuous integration and see how much faster the action runs now that it doesn't have to rebuild\n    the container image each time.\n    \n\n\n## Contributions\nAlways welcome! Please open a PR or an issue, and remember to follow the [Gopher Code of Conduct](https://www.gophercon.com/page/1475132/code-of-conduct).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdlemel8%2Fgophercon-2021-go-action","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdlemel8%2Fgophercon-2021-go-action","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdlemel8%2Fgophercon-2021-go-action/lists"}