Skip to content

Identifier gates, error disclosure, and authserver 0.2.0 alignment #17

Identifier gates, error disclosure, and authserver 0.2.0 alignment

Identifier gates, error disclosure, and authserver 0.2.0 alignment #17

name: Lint workflows
# Catches workflow YAML / shell-in-`run:` regressions at PR time so a
# typo can't reach a release tag and surface only when a publish run
# fails. The shell scripts under scripts/ are in the same category — a
# break in them surfaces only when someone reaches for them after a
# release, which is the worst moment to discover it — so they are
# shellchecked and, where they have a suite, tested here too.
#
# `.github/scripts/*.sh` is in scope for the same reason. Those scripts
# serve the weekly conformance drift workflow, so a break in them surfaces
# late and quietly — and the way it surfaces is a green run, because what
# they guard against is a check that under-reports. Shellcheck alone would
# not have been enough for them, so they carry their own tests here as
# well, next to backport-fixes.test.sh.
#
# Scoped to `.github/workflows/**`, `.github/scripts/*.sh` and
# `scripts/*.sh` to keep CI overhead off unrelated PRs.
on:
pull_request:
paths:
- ".github/workflows/**"
- ".github/scripts/*.sh"
- "scripts/*.sh"
push:
branches:
- main
paths:
- ".github/workflows/**"
- ".github/scripts/*.sh"
- "scripts/*.sh"
permissions:
contents: read
jobs:
# This job runs actionlint, shellcheck and the backport-fixes suite — the id
# is narrower than the work. Do not rename it: the required status check is
# named after the job id, exactly as the branch protection rule depends on
# the workflow `name:` above. Renaming either silently drops the check from
# the required set. Add steps here instead.
actionlint:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Pulls the matching actionlint binary release from GitHub Releases
# via the upstream download script. The script is fetched by commit
# SHA (not a mutable tag) and sha256-verified before it runs — this
# closes Scorecard's "downloadThenRun not pinned by hash" gap. The
# script then checksum-verifies the actionlint binary it pulls from
# the matching release.
#
# To bump: change ACTIONLINT_VERSION, set ACTIONLINT_SCRIPT_SHA to the
# commit the new tag points at (`gh api repos/rhysd/actionlint/commits/vX.Y.Z -q .sha`),
# and update ACTIONLINT_SCRIPT_SHA256 to that file's sha256.
#
# Install dir is passed explicitly as the script's second positional
# arg so the workflow doesn't couple to the script's internal default
# of $PWD (which happens to be $GITHUB_WORKSPACE after checkout —
# a coincidence, not a contract).
- name: Install actionlint
env:
ACTIONLINT_VERSION: "1.7.7"
ACTIONLINT_SCRIPT_SHA: "03d0035246f3e81f36aed592ffb4bebf33a03106"
ACTIONLINT_SCRIPT_SHA256: "221d1d16c03e4e4fcd867de34104e8d479bdce20ccdfa553b9a5c0dc29bf6af2"
ACTIONLINT_INSTALL_DIR: ${{ runner.temp }}/actionlint
run: |
mkdir -p "${ACTIONLINT_INSTALL_DIR}"
script="${ACTIONLINT_INSTALL_DIR}/download-actionlint.bash"
curl -fsSL -o "${script}" \
"https://raw.githubusercontent.com/rhysd/actionlint/${ACTIONLINT_SCRIPT_SHA}/scripts/download-actionlint.bash"
echo "${ACTIONLINT_SCRIPT_SHA256} ${script}" | sha256sum -c -
bash "${script}" "${ACTIONLINT_VERSION}" "${ACTIONLINT_INSTALL_DIR}"
echo "${ACTIONLINT_INSTALL_DIR}" >> "${GITHUB_PATH}"
"${ACTIONLINT_INSTALL_DIR}/actionlint" -version
# `-shellcheck=shellcheck` makes the shellcheck dependency explicit
# rather than relying on actionlint's implicit lookup against the
# runner image's $PATH; if the Ubuntu image ever drops shellcheck the
# job fails loudly instead of silently degrading.
- name: Run actionlint
run: actionlint -color -shellcheck=shellcheck
# actionlint only reaches shell inside `run:` blocks. The scripts
# those blocks invoke need shellcheck run against them directly.
- name: Shellcheck the repo scripts
run: shellcheck scripts/*.sh
# backport-fixes.sh resolves --from as a branch or a tag against
# origin, and its failure modes (a fetch that fails for a reason
# other than "no such ref") are only reachable with a real remote.
# The suite builds throwaway repos in a temp dir — no network.
- name: Test backport-fixes.sh
run: scripts/backport-fixes.test.sh
# The scripts the drift workflow invokes. Same argument as the repo
# scripts above: actionlint only reaches shell inside `run:` blocks.
- name: Shellcheck the workflow support scripts
run: shellcheck .github/scripts/*.sh
# Shellcheck is the only other gate on the conformance drift scripts,
# and it cannot see the way they break: a loosened id regex that drops
# cases, or a `diff` whose exit code stops being read, is valid shell.
# The result is a check that reports green while guarding nothing, on a
# weekly schedule where nobody is watching — and it would stay unnoticed
# until a real re-tightening slipped through, which is the failure that
# check exists to prevent. These controls pin the detection itself. They
# need neither Maven nor the catalog checkout, so they run here.
- name: Test conformance-case-body-drift.sh
run: .github/scripts/conformance-case-body-drift.test.sh