Skip to content

Commit b204b82

Browse files
ci: lint workflows with actionlint
Add a Lint workflow that runs `mise run lint` on pushes to main and on pull requests. actionlint and shellcheck are pinned in mise.toml and mise.lock. Document the local linting commands in CONTRIBUTING.md.
1 parent 23f97c5 commit b204b82

4 files changed

Lines changed: 150 additions & 0 deletions

File tree

‎.github/workflows/lint.yml‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
name: Lint
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
8+
permissions: {}
9+
10+
# Cancelling a push to main would leave that commit unlinted.
11+
concurrency:
12+
group: ${{ github.workflow }}-${{ github.ref }}
13+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
14+
15+
jobs:
16+
lint:
17+
name: Lint
18+
runs-on: ubuntu-latest
19+
permissions:
20+
contents: read # required for checkout
21+
steps:
22+
- name: Checkout
23+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
24+
with:
25+
persist-credentials: false
26+
- name: Setup mise
27+
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
28+
with:
29+
minimum_release_age: 7d
30+
- name: Run lint
31+
run: mise run lint

‎CONTRIBUTING.md‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,3 +13,19 @@ bash scripts/compute-workflow-sha256.sh
1313
This regenerates `<name>/workflow-sha256`, a checksum of the workflow file. Commit the resulting diff alongside your workflow change — this is what makes the change visible to release-please for that Component.
1414

1515
CI enforces this on every pull request via `bash scripts/compute-workflow-sha256.sh --check`, which fails if any `workflow-sha256` file is out of date.
16+
17+
## Linting
18+
19+
Workflows are linted with [actionlint](https://github.com/rhysd/actionlint), which also runs [shellcheck](https://github.com/koalaman/shellcheck) on `run:` scripts. Both tools are pinned in `mise.toml` and `mise.lock`. Install them with [mise](https://mise.jdx.dev):
20+
21+
```sh
22+
mise install --locked
23+
```
24+
25+
Then:
26+
27+
```sh
28+
mise run lint
29+
```
30+
31+
CI runs the same command on every pull request and on every push to `main`.

‎mise.lock‎

Lines changed: 90 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎mise.toml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
[settings]
2+
minimum_release_age = "7d"
3+
lockfile = true
4+
5+
[tools]
6+
"aqua:actionlint" = "1.7.12"
7+
"aqua:koalaman/shellcheck" = "0.11.0"
8+
9+
[tasks."lint:actionlint"]
10+
run = "actionlint"
11+
12+
[tasks.lint]
13+
depends = [ "lint:actionlint" ]

0 commit comments

Comments
 (0)