Repository navigation
Identifier gates, error disclosure, and authserver 0.2.0 alignment #17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Lint workflows | |
| # Catches workflow YAML / shell-in-`run:` regressions at PR time so a | |
| # typo can't reach a release tag and surface only when a publish run | |
| # fails. The shell scripts under scripts/ are in the same category — a | |
| # break in them surfaces only when someone reaches for them after a | |
| # release, which is the worst moment to discover it — so they are | |
| # shellchecked and, where they have a suite, tested here too. | |
| # | |
| # `.github/scripts/*.sh` is in scope for the same reason. Those scripts | |
| # serve the weekly conformance drift workflow, so a break in them surfaces | |
| # late and quietly — and the way it surfaces is a green run, because what | |
| # they guard against is a check that under-reports. Shellcheck alone would | |
| # not have been enough for them, so they carry their own tests here as | |
| # well, next to backport-fixes.test.sh. | |
| # | |
| # Scoped to `.github/workflows/**`, `.github/scripts/*.sh` and | |
| # `scripts/*.sh` to keep CI overhead off unrelated PRs. | |
| on: | |
| pull_request: | |
| paths: | |
| - ".github/workflows/**" | |
| - ".github/scripts/*.sh" | |
| - "scripts/*.sh" | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - ".github/workflows/**" | |
| - ".github/scripts/*.sh" | |
| - "scripts/*.sh" | |
| permissions: | |
| contents: read | |
| jobs: | |
| # This job runs actionlint, shellcheck and the backport-fixes suite — the id | |
| # is narrower than the work. Do not rename it: the required status check is | |
| # named after the job id, exactly as the branch protection rule depends on | |
| # the workflow `name:` above. Renaming either silently drops the check from | |
| # the required set. Add steps here instead. | |
| actionlint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| # Pulls the matching actionlint binary release from GitHub Releases | |
| # via the upstream download script. The script is fetched by commit | |
| # SHA (not a mutable tag) and sha256-verified before it runs — this | |
| # closes Scorecard's "downloadThenRun not pinned by hash" gap. The | |
| # script then checksum-verifies the actionlint binary it pulls from | |
| # the matching release. | |
| # | |
| # To bump: change ACTIONLINT_VERSION, set ACTIONLINT_SCRIPT_SHA to the | |
| # commit the new tag points at (`gh api repos/rhysd/actionlint/commits/vX.Y.Z -q .sha`), | |
| # and update ACTIONLINT_SCRIPT_SHA256 to that file's sha256. | |
| # | |
| # Install dir is passed explicitly as the script's second positional | |
| # arg so the workflow doesn't couple to the script's internal default | |
| # of $PWD (which happens to be $GITHUB_WORKSPACE after checkout — | |
| # a coincidence, not a contract). | |
| - name: Install actionlint | |
| env: | |
| ACTIONLINT_VERSION: "1.7.7" | |
| ACTIONLINT_SCRIPT_SHA: "03d0035246f3e81f36aed592ffb4bebf33a03106" | |
| ACTIONLINT_SCRIPT_SHA256: "221d1d16c03e4e4fcd867de34104e8d479bdce20ccdfa553b9a5c0dc29bf6af2" | |
| ACTIONLINT_INSTALL_DIR: ${{ runner.temp }}/actionlint | |
| run: | | |
| mkdir -p "${ACTIONLINT_INSTALL_DIR}" | |
| script="${ACTIONLINT_INSTALL_DIR}/download-actionlint.bash" | |
| curl -fsSL -o "${script}" \ | |
| "https://raw.githubusercontent.com/rhysd/actionlint/${ACTIONLINT_SCRIPT_SHA}/scripts/download-actionlint.bash" | |
| echo "${ACTIONLINT_SCRIPT_SHA256} ${script}" | sha256sum -c - | |
| bash "${script}" "${ACTIONLINT_VERSION}" "${ACTIONLINT_INSTALL_DIR}" | |
| echo "${ACTIONLINT_INSTALL_DIR}" >> "${GITHUB_PATH}" | |
| "${ACTIONLINT_INSTALL_DIR}/actionlint" -version | |
| # `-shellcheck=shellcheck` makes the shellcheck dependency explicit | |
| # rather than relying on actionlint's implicit lookup against the | |
| # runner image's $PATH; if the Ubuntu image ever drops shellcheck the | |
| # job fails loudly instead of silently degrading. | |
| - name: Run actionlint | |
| run: actionlint -color -shellcheck=shellcheck | |
| # actionlint only reaches shell inside `run:` blocks. The scripts | |
| # those blocks invoke need shellcheck run against them directly. | |
| - name: Shellcheck the repo scripts | |
| run: shellcheck scripts/*.sh | |
| # backport-fixes.sh resolves --from as a branch or a tag against | |
| # origin, and its failure modes (a fetch that fails for a reason | |
| # other than "no such ref") are only reachable with a real remote. | |
| # The suite builds throwaway repos in a temp dir — no network. | |
| - name: Test backport-fixes.sh | |
| run: scripts/backport-fixes.test.sh | |
| # The scripts the drift workflow invokes. Same argument as the repo | |
| # scripts above: actionlint only reaches shell inside `run:` blocks. | |
| - name: Shellcheck the workflow support scripts | |
| run: shellcheck .github/scripts/*.sh | |
| # Shellcheck is the only other gate on the conformance drift scripts, | |
| # and it cannot see the way they break: a loosened id regex that drops | |
| # cases, or a `diff` whose exit code stops being read, is valid shell. | |
| # The result is a check that reports green while guarding nothing, on a | |
| # weekly schedule where nobody is watching — and it would stay unnoticed | |
| # until a real re-tightening slipped through, which is the failure that | |
| # check exists to prevent. These controls pin the detection itself. They | |
| # need neither Maven nor the catalog checkout, so they run here. | |
| - name: Test conformance-case-body-drift.sh | |
| run: .github/scripts/conformance-case-body-drift.test.sh |