Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
ca314e4
fix(executable-bit): account for custom Git helper paths
kjanat Sep 26, 2026
4808c30
Merge branch 'stack/action-executable-bit' into stack/action-composit…
kjanat Sep 26, 2026
817bed1
Merge branch 'stack/action-composite-scripts' into stack/action-javas…
kjanat Sep 26, 2026
e8fd536
feat(output)!: unify analysis JSON results
kjanat Sep 26, 2026
5d08dbd
fix(ci): check unified analysis results
kjanat Sep 26, 2026
361766e
fix(release): validate unified Action results
kjanat Sep 26, 2026
36e53b0
fix(action): preserve result configuration order
kjanat Sep 26, 2026
acb73b2
fix(cli): classify errors after command selection
kjanat Sep 26, 2026
7e63e29
Update CI workflows and dependencies
kjanat Sep 10, 2026
726ad7b
Update @kjlint/changelog-rss and enable source imports
kjanat Sep 10, 2026
71fbe33
Make JavaScript tooling checks pass on the complete workspace
kjanat Sep 26, 2026
9dae283
Expand changelog package entrypoints consistently
kjanat Sep 26, 2026
cb5b04d
Normalize changelog package metadata with npm
kjanat Sep 26, 2026
5f97805
refactor(test): keep published Action tests static
kjanat Sep 26, 2026
7adee8b
Merge analysis result test cleanup into tooling
kjanat Sep 26, 2026
7be2f3a
test: inline published Action assertions with actions-shells
kjanat Sep 26, 2026
70d4813
Merge inline published Action checks into tooling
kjanat Sep 26, 2026
201a85e
test: remove YAML implementation assertions
kjanat Sep 26, 2026
bb0cc23
Merge smoke test cleanup into tooling
kjanat Sep 26, 2026
231c20b
Normalize workspace metadata and update formatters
kjanat Sep 26, 2026
9d21154
Keep release-triggered Pages builds current
kjanat Sep 26, 2026
2cf1ae9
Merge reporting fixes and verify workspace reader
kjanat Oct 2, 2026
96d58cc
fix(dev): install the configured task runner
kjanat Oct 3, 2026
6833700
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
e56d152
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
30645e9
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
a3c91e5
fix(playground): distinguish source from releases
kjanat Oct 3, 2026
690d823
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
80583a8
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
cdcf9b6
test(playground): await build version tests
kjanat Oct 3, 2026
6c304a5
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
f0711dd
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
2bf240c
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
65aa7a8
Merge branch 'stack/analysis-results' into jiggamariggama
kjanat Oct 3, 2026
752e817
merge: carry partial result and deadline fixes
kjanat Oct 3, 2026
0901d86
merge: update cancellation expectations
kjanat Oct 3, 2026
ec31a65
merge: carry Action timeout findings into setup
kjanat Oct 3, 2026
9fae466
merge: carry empty diagnostics regression
kjanat Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .dprint.jsonc
Original file line number Diff line number Diff line change
Expand Up @@ -74,15 +74,15 @@
"npm:@dprint/dockerfile@0.6.0",
"npm:@dprint/dockerfile@0.6.0",
"npm:@dprint/typescript@0.96.1",
"npm:@dprint/markdown@0.23.2",
"npm:@dprint/json@0.23.0",
"npm:@jakebailey/dprint-plugin-gofumpt@0.0.17",
"npm:@dprint/markdown@0.24.0",
"npm:@dprint/json@0.24.0",
"npm:@jakebailey/dprint-plugin-gofumpt@0.0.18",
"https://plugins.dprint.dev/sargunv/dprint-cmakefmt-0.1.0.wasm",
"npm:dprint-plugin-yaml@0.6.0",
"npm:dprint-plugin-malva@0.16.0",
"npm:dprint-plugin-markup@0.27.3",
"npm:dprint-plugin-markup@0.27.5",
"https://plugins.dprint.dev/kjanat/pwsh-0.2.0.wasm",
"https://plugins.dprint.dev/kjanat/shfmt-1.1.0.wasm",
"https://plugins.dprint.dev/kjanat/shfmt-1.1.1.wasm",
"https://plugins.dprint.dev/kjanat/sortpackagejson-0.2.1.wasm",
"https://plugins.dprint.dev/kjanat/svg-v0.4.1.wasm",
],
Expand Down
35 changes: 23 additions & 12 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,18 +65,28 @@ jobs:
steps:
- *ActCheckNocred
- *GoGomod
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
- &NodeTooling
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with: { node-version-file: .node-version, package-manager-cache: false }
- &Runner { uses: kjanat/runner@8baa9ee978cfed038b98741749673c788ff161d1 } # v0.26.1
- &Runner { uses: kjanat/runner@8baa9ee978cfed038b98741749673c788ff161d1 } # v0.26.2
- &Pandoc { name: Install Pandoc, uses: $/.github/actions/setup-pandoc }
- name: Install JavaScript dependencies
run: runner install --frozen
- name: Build command manual
run: run make:man
- name: Build and test playground
run: run --dir playground -s make:build make:test
run: run -s playground:make:build playground:make:test
- name: Lint JavaScript workspaces
run: run lint
javascript:
name: JavaScript
runs-on: ubuntu-latest
steps:
- *ActCheckNocred
- *NodeTooling
- *Runner
- name: Install dependencies and test JavaScript tooling
run: runner install --frozen test:js
release-snapshot:
name: Release snapshot
runs-on: ubuntu-latest
Expand All @@ -87,6 +97,8 @@ jobs:
- &Go { uses: *SetupGo, with: *GoMod }
- *Pandoc
- *Runner
- name: Install syft for SBOM generation
uses: anchore/sbom-action/download-syft@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
- uses: &SetupNode actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with: { node-version: "24", package-manager-cache: false }
- name: Build JavaScript Action release files outside the checkout
Expand All @@ -95,8 +107,6 @@ jobs:
tag="$(git describe --tags --abbrev=0 --match 'v[0-9]*.[0-9]*.[0-9]*' --exclude '*-*')"
node scripts/build-action-release.mjs --out-dir "${RUNNER_TEMP}/actionlint-action" --version "${tag#v}"
- run: run make:man/actionlint.1
- name: Install syft for SBOM generation
uses: anchore/sbom-action/download-syft@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with: { version: v2.18.0, args: release --snapshot --clean }
- name: Smoke-test the linux/amd64 snapshot binary
Expand Down Expand Up @@ -158,13 +168,14 @@ jobs:
run: docker build --target action -t actionlint:action-test .
- name: Check Docker Action compatibility
run: bash scripts/test-docker-action.bash actionlint:action-test
- name: Lint Dockerfile with hadolint
run: docker run --rm -i hadolint/hadolint hadolint --ignore DL3018 --strict-labels
--require-label org.opencontainers.image.source:url
--require-label org.opencontainers.image.licenses:spdx
- < Dockerfile
- name: Lint Dockerfile with droast
uses: immanuwell/dockerfile-roast@1c87b2aa189338c24db4acde40864dae8994de8f # 1.7.0
- parallel:
- name: Lint Dockerfile with hadolint
run: docker run --rm -i hadolint/hadolint hadolint --ignore DL3018 --strict-labels
--require-label org.opencontainers.image.source:url
--require-label org.opencontainers.image.licenses:spdx
- < Dockerfile
- name: Lint Dockerfile with droast
uses: immanuwell/dockerfile-roast@1c87b2aa189338c24db4acde40864dae8994de8f # 1.7.0
action:
name: GitHub Action
strategy:
Expand Down
37 changes: 24 additions & 13 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,24 +15,35 @@ jobs:
build:
if: >-
github.event_name != 'workflow_run' ||
(github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' &&
(github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'release' &&
Comment thread
kjanat marked this conversation as resolved.
github.event.workflow_run.head_repository.full_name == github.repository)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with: { persist-credentials: false, fetch-depth: 0, ref: "${{ github.event.workflow_run.head_sha || github.sha }}" }
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with: { go-version-file: go.mod }
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with: { node-version-file: .node-version, package-manager-cache: false }
- uses: $/.github/actions/setup-pandoc
- uses: kjanat/runner@8baa9ee978cfed038b98741749673c788ff161d1 # v0.26.2
- name: Install JavaScript dependencies
run: runner install --frozen
- name: Build command manual
run: run make:man
with: {
persist-credentials: false,
fetch-depth: 0,
ref: "${{ github.event_name == 'workflow_run' && github.event.repository.default_branch || github.sha }}",
Comment thread
kjanat marked this conversation as resolved.
}
- parallel:
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with: { go-version-file: go.mod }
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with: { node-version-file: .node-version, package-manager-cache: false }
- uses: $/.github/actions/setup-pandoc
- uses: kjanat/runner@8baa9ee978cfed038b98741749673c788ff161d1 # v0.26.2
- parallel:
- name: Install JavaScript dependencies
run: runner install --frozen
- name: Build command manual
run: run make:man
- name: Build and test playground
run: run --dir playground -s make:build make:test
env: { GH_TOKEN: "${{ github.token }}" }
run: |
if latest_release="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq '.tag_name')"; then
export ACTIONLINT_LATEST_RELEASE="${latest_release}"
fi
run -s playground:make:build playground:make:test
- uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5
with: { path: playground/dist }

Expand Down
2 changes: 2 additions & 0 deletions .mise.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,15 @@ actionlint = { version = "latest", minimum_release_age = "0s", depends = ["sh
dprint = { version = "latest", lazy = true }
go = { version = "latest" }
golangci-lint = { version = "latest", lazy = true }
runner-run = "latest"
shellcheck = { version = "latest" }
tombi = { version = "latest", lazy = true }

[tool_alias]
"actionlint" = "github:kjanat/actionlint"
"actionlint-kjanat" = "github:kjanat/actionlint"
"actionlint-rhysd" = "github:rhysd/actionlint"
"runner-run" = "github:kjanat/runner"

[settings]
minimum_release_age_excludes = [
Expand Down
2 changes: 2 additions & 0 deletions .npmrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
allow-git=root

8 changes: 4 additions & 4 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -287,15 +287,15 @@ Visit [`playground/README.md`].

## How to deploy playground

The [Pages workflow] deploys on pushes to `master` and after successful Release runs triggered by pushes within this repository. Release-triggered builds check out that release's commit. The build job has read-only repository access and builds the bundle with `make -C playground build`, packages `playground/dist` together with the manual, and uploads it through `actions/upload-pages-artifact`.
The [Pages workflow] deploys on pushes to `master` and after successful Release runs triggered by published releases within this repository. Release-triggered builds check out the current default branch. The source badge and documentation links identify the built revision; a separate latest-release badge links to the published release. The build job has read-only repository access and builds the bundle with `run playground:make:build`, packages `playground/dist` together with the manual, and uploads it through `actions/upload-pages-artifact`.

Only the separate deployment job receives Pages write and OIDC permissions.

To check a build locally before pushing:
Install the tools in `.mise.toml` with `mise install` and activate mise in your shell. This makes the configured runner's `run` command available. Then check a build locally:

```sh
make -C playground build
npm run preview
run playground:make:build
run playground:preview
Comment thread
kjanat marked this conversation as resolved.
```

## Maintain auto-generated sources
Expand Down
4 changes: 3 additions & 1 deletion distribution/npm/facade/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,9 @@
"exports": {
"./package.json": "./package.json",
"./schema": "./actionlint.schema.json",
"./result": { "types": "./types/result.d.ts" },
"./result": {
"types": "./types/result.d.ts"
},
"./result.schema.json": "./schemas/results/v1.schema.json",
"./schemas/*": "./schemas/*"
},
Expand Down
1 change: 0 additions & 1 deletion docs/checks.md
Original file line number Diff line number Diff line change
Expand Up @@ -1022,7 +1022,6 @@ shell and working directory. Findings point to `action.yml` or `action.yaml`.
Remote action contents are not downloaded for these checks.

[workflow-scripts-doc]: https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/add-scripts

<a id="check-shellcheck-integ"></a>

## [shellcheck][shellcheck] integration for `run:`
Expand Down
Loading
Loading