-
Notifications
You must be signed in to change notification settings - Fork 3.1k
65 lines (59 loc) · 2.62 KB
/
Copy pathactionlint.yml
File metadata and controls
65 lines (59 loc) · 2.62 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
# Lints the GitHub Actions workflows themselves with actionlint
# (https://github.com/rhysd/actionlint): workflow syntax, expression contexts,
# and embedded shell (via shellcheck). actionlint is run through
# github/super-linter (restricted to the GitHub Actions validator) because the
# ASF org allowed-actions policy permits GitHub-owned actions but not the
# stand-alone actionlint action/image. Only runs when a workflow file changes.
name: Actionlint
on:
push:
paths:
- '.github/workflows/**'
pull_request:
paths:
- '.github/workflows/**'
# cancel superseded runs on the same ref (e.g. rapid pushes to a branch)
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
actionlint:
name: Lint GitHub Actions workflows
runs-on: ubuntu-latest
steps:
- name: Checkout maven
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# super-linter needs full history to resolve the commit range
fetch-depth: 0
# super-linter is GitHub-owned, so it satisfies the ASF allowed-actions
# policy (a stand-alone actionlint action/image is not on the allowlist).
# VALIDATE_GITHUB_ACTIONS restricts it to actionlint only; other linters
# (shellcheck, yaml, ...) can be enabled later via more VALIDATE_* flags.
- name: Lint workflows with actionlint (via super-linter)
uses: github/super-linter/slim@b807e99ddd37e444d189cfd2c2ca1274d8ae8ef1 # v7
env:
VALIDATE_ALL_CODEBASE: true
VALIDATE_GITHUB_ACTIONS: true
# DEFAULT_BRANCH is left unset so super-linter auto-detects it,
# which keeps this working on forks whose default branch is not master.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}