mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 19:53:11 +00:00
The self-CI gate ran `./actionlint -shellcheck=`, and the empty value silently disabled the shell-linting half of the check — so every `run:` body in the reusable workflows this repo publishes was unlinted, on the exact path that deploys to AWS. Measured against the pinned actionlint 1.7.12 and the shellcheck the ubuntu-latest runner ships (0.9.0-1), the real backlog was 5 findings, not the 4 the old comment claimed. Three were genuine and are fixed in the shell: - cd-cdk.yaml "Publish .NET project" (SC2046): the project path was interpolated inline and `$(dirname ...)` was unquoted, so a path containing whitespace split into several arguments. Now passed via env indirection and quoted, which also removes the last inline expression interpolation from that step. - cd-cdk.yaml / ci-python-sam.yaml "Install Python dependencies" (SC2044 x2): `for req in $(find ...)` word-split and globbed every path found. Replaced with a NUL-delimited `while read` loop. Two are deliberate and are suppressed per-line, with the reasoning in a comment directly above: - cd-sam.yaml `sam deploy ... $PARAMS` and cd-cdk.yaml `cdk deploy $STACKS` (SC2086 x2) rely on word-splitting so multiple parameter overrides / stack selectors reach the CLI as separate argv entries. Quoting them would collapse each into a single argument and break every parameterised or multi-stack deploy, so they keep the unquoted expansion and carry a scoped `# shellcheck disable=SC2086`. The gate now runs plain `./actionlint` (shellcheck defaults to the binary on PATH) and prints `shellcheck --version` first, so the check fails loudly if a future runner image drops it instead of quietly linting less. |
||
|---|---|---|
| .. | ||
| callable-dependency-review.yaml | ||
| callable-labeler.yaml | ||
| cd-cdk.yaml | ||
| cd-dotnet-eb.yaml | ||
| cd-mobile-ios.yaml | ||
| cd-sam.yaml | ||
| ci-dotnet.yaml | ||
| ci-python-app.yaml | ||
| ci-python-sam.yaml | ||
| ci-static.yaml | ||
| ci-typescript-cdk.yaml | ||
| ci-typescript-frontend.yaml | ||
| ci.yaml | ||
| compliance-audit.yaml | ||
| labeler.yaml | ||