diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml new file mode 100644 index 0000000..d306f40 --- /dev/null +++ b/.github/workflows/lint.yml @@ -0,0 +1,31 @@ +name: Lint + +on: + push: + branches: [main] + pull_request: + +permissions: {} + +# Cancelling a push to main would leave that commit unlinted. +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +jobs: + lint: + name: Lint + runs-on: ubuntu-latest + permissions: + contents: read # required for checkout + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Setup mise + uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 + with: + minimum_release_age: 7d + - name: Run lint + run: mise run lint diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 835dd43..e721f35 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -13,3 +13,19 @@ bash scripts/compute-workflow-sha256.sh This regenerates `/workflow-sha256`, a checksum of the workflow file. Commit the resulting diff alongside your workflow change — this is what makes the change visible to release-please for that Component. CI enforces this on every pull request via `bash scripts/compute-workflow-sha256.sh --check`, which fails if any `workflow-sha256` file is out of date. + +## Linting + +Workflows are linted with [actionlint](https://github.com/rhysd/actionlint), which also runs [shellcheck](https://github.com/koalaman/shellcheck) on inline `run:` scripts. Shell scripts committed to the repository (`*.sh`, e.g. under `scripts/`) are linted with shellcheck directly. Both tools are pinned in `mise.toml` and `mise.lock`. Install them with [mise](https://mise.jdx.dev): + +```sh +mise install --locked +``` + +Then: + +```sh +mise run lint +``` + +CI runs the same command on every pull request and on every push to `main`. diff --git a/mise.lock b/mise.lock new file mode 100644 index 0000000..c4d29c5 --- /dev/null +++ b/mise.lock @@ -0,0 +1,90 @@ +# @generated - this file is auto-generated by `mise lock` https://mise.jdx.dev/dev-tools/mise-lock.html + +lockfile_version = 2 + +[[tools."aqua:actionlint"]] +version = "1.7.12" +backend = "aqua:actionlint" +specifiers = ["1.7.12"] + +[tools."aqua:actionlint"."platforms.linux-arm64"] +checksum = "sha256:325e971b6ba9bfa504672e29be93c24981eeb1c07576d730e9f7c8805afff0c6" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_arm64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924897" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.linux-arm64-musl"] +checksum = "sha256:325e971b6ba9bfa504672e29be93c24981eeb1c07576d730e9f7c8805afff0c6" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_arm64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924897" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.linux-x64"] +checksum = "sha256:8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924896" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.linux-x64-musl"] +checksum = "sha256:8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924896" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.macos-arm64"] +checksum = "sha256:aba9ced2dee8d27fecca3dc7feb1a7f9a52caefa1eb46f3271ea66b6e0e6953f" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_darwin_arm64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924893" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.macos-x64"] +checksum = "sha256:5b44c3bc2255115c9b69e30efc0fecdf498fdb63c5d58e17084fd5f16324c644" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_darwin_amd64.tar.gz" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924880" +provenance = "github-attestations" + +[tools."aqua:actionlint"."platforms.windows-x64"] +checksum = "sha256:6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9" +url = "https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_windows_amd64.zip" +url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/384924919" +provenance = "github-attestations" + +[[tools."aqua:koalaman/shellcheck"]] +version = "0.11.0" +backend = "aqua:koalaman/shellcheck" +specifiers = ["0.11.0"] + +[tools."aqua:koalaman/shellcheck"."platforms.linux-arm64"] +checksum = "sha256:12b331c1d2db6b9eb13cfca64306b1b157a86eb69db83023e261eaa7e7c14588" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.aarch64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056934" + +[tools."aqua:koalaman/shellcheck"."platforms.linux-arm64-musl"] +checksum = "sha256:12b331c1d2db6b9eb13cfca64306b1b157a86eb69db83023e261eaa7e7c14588" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.aarch64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056934" + +[tools."aqua:koalaman/shellcheck"."platforms.linux-x64"] +checksum = "sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.x86_64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056942" + +[tools."aqua:koalaman/shellcheck"."platforms.linux-x64-musl"] +checksum = "sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.linux.x86_64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056942" + +[tools."aqua:koalaman/shellcheck"."platforms.macos-arm64"] +checksum = "sha256:56affdd8de5527894dca6dc3d7e0a99a873b0f004d7aabc30ae407d3f48b0a79" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.darwin.aarch64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056932" + +[tools."aqua:koalaman/shellcheck"."platforms.macos-x64"] +checksum = "sha256:3c89db4edcab7cf1c27bff178882e0f6f27f7afdf54e859fa041fca10febe4c6" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.darwin.x86_64.tar.xz" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056930" + +[tools."aqua:koalaman/shellcheck"."platforms.windows-x64"] +checksum = "sha256:8a4e35ab0b331c85d73567b12f2a444df187f483e5079ceffa6bda1faa2e740e" +url = "https://github.com/koalaman/shellcheck/releases/download/v0.11.0/shellcheck-v0.11.0.zip" +url_api = "https://api.github.com/repos/koalaman/shellcheck/releases/assets/279056944" diff --git a/mise.toml b/mise.toml new file mode 100644 index 0000000..8cd129b --- /dev/null +++ b/mise.toml @@ -0,0 +1,17 @@ +[settings] +minimum_release_age = "7d" +lockfile = true + +[tools] +"aqua:actionlint" = "1.7.12" +"aqua:koalaman/shellcheck" = "0.11.0" + +[tasks."lint:actionlint"] +run = "actionlint" + +[tasks."lint:shellcheck"] +shell = "bash -euo pipefail -c" +run = "git ls-files -z --cached --others --exclude-standard '*.sh' | xargs -0 -r shellcheck" + +[tasks.lint] +depends = [ "lint:actionlint", "lint:shellcheck" ] diff --git a/scripts/check-release-please-config.sh b/scripts/check-release-please-config.sh index 35753c5..e9aa872 100755 --- a/scripts/check-release-please-config.sh +++ b/scripts/check-release-please-config.sh @@ -40,6 +40,7 @@ fi # --- root key ordering: $schema first, lexicographic, packages last --- mapfile -t root_keys < <(jq -r 'keys_unsorted[]' "$CONFIG") +# shellcheck disable=SC2016 # literal key name, not an expansion if [[ "${root_keys[0]-}" != '$schema' ]]; then say_err "root key order: first key must be \"\$schema\" (got \"${root_keys[0]-}\")" ((failures += 1)) @@ -52,6 +53,7 @@ fi mid_keys=() for k in "${root_keys[@]}"; do + # shellcheck disable=SC2016 # literal key name, not an expansion [[ "$k" == '$schema' || "$k" == 'packages' ]] && continue mid_keys+=("$k") done diff --git a/scripts/compute-workflow-sha256.sh b/scripts/compute-workflow-sha256.sh index 59e1488..f465a1d 100755 --- a/scripts/compute-workflow-sha256.sh +++ b/scripts/compute-workflow-sha256.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash set -uo pipefail -cd "$(dirname "$0")/.." +cd "$(dirname "$0")/.." || exit 1 check=false if [[ "${1:-}" == "--check" ]]; then