Skip to content

ci: lint GitHub Actions - #36

Merged
IzumiSy merged 3 commits into
mainfrom
ci/lint-github-actions
Oct 2, 2026
Merged

IzumiSy merged 3 commits into
mainfrom
ci/lint-github-actions

Conversation

@IzumiSy

@IzumiSy IzumiSy commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Motivation

GitHub Actions workflows and the repository's composite action need automated syntax and security checks before they are merged.

Design Decision

Chosen approach

Use the referenced Aqua-managed toolchain: actionlint for workflow validation, ghalint for GitHub Actions hardening policies, and zizmor for static security analysis. The workflow also checks the root action.yml, which is this repository's composite action metadata.

Trade-offs

Existing workflows now pin third-party actions by commit SHA and declare job-scoped permissions, timeouts, and disabled checkout credentials so the new policies pass without exclusions.

Summary

  • Add a path-filtered GitHub Actions lint and security workflow.
  • Pin the linter toolchain in aqua.yaml.
  • Harden existing workflows and the composite action for the new checks.

@IzumiSy

IzumiSy commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@copilot Fix CI errors

Co-authored-by: IzumiSy <982850+IzumiSy@users.noreply.github.com>

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@copilot Fix CI errors

Fixed the zizmor template-injection CI failure in fdc8773 by passing the base ref through an environment variable and shell-quoting it.

@IzumiSy
IzumiSy marked this pull request as ready for review October 2, 2026 02:50
@IzumiSy
IzumiSy merged commit 44b2f7e into main Oct 2, 2026
5 checks passed
@IzumiSy
IzumiSy deleted the ci/lint-github-actions branch October 2, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants