.github/.github/workflows
Adam Moussa 5889d52333
ci: enable actionlint's shellcheck integration in self-CI
The self-CI gate ran `./actionlint -shellcheck=`, and the empty value
silently disabled the shell-linting half of the check — so every `run:`
body in the reusable workflows this repo publishes was unlinted, on the
exact path that deploys to AWS.

Measured against the pinned actionlint 1.7.12 and the shellcheck the
ubuntu-latest runner ships (0.9.0-1), the real backlog was 5 findings,
not the 4 the old comment claimed. Three were genuine and are fixed in
the shell:

- cd-cdk.yaml "Publish .NET project" (SC2046): the project path was
  interpolated inline and `$(dirname ...)` was unquoted, so a path
  containing whitespace split into several arguments. Now passed via
  env indirection and quoted, which also removes the last inline
  expression interpolation from that step.
- cd-cdk.yaml / ci-python-sam.yaml "Install Python dependencies"
  (SC2044 x2): `for req in $(find ...)` word-split and globbed every
  path found. Replaced with a NUL-delimited `while read` loop.

Two are deliberate and are suppressed per-line, with the reasoning in a
comment directly above:

- cd-sam.yaml `sam deploy ... $PARAMS` and cd-cdk.yaml
  `cdk deploy $STACKS` (SC2086 x2) rely on word-splitting so multiple
  parameter overrides / stack selectors reach the CLI as separate argv
  entries. Quoting them would collapse each into a single argument and
  break every parameterised or multi-stack deploy, so they keep the
  unquoted expansion and carry a scoped `# shellcheck disable=SC2086`.

The gate now runs plain `./actionlint` (shellcheck defaults to the
binary on PATH) and prints `shellcheck --version` first, so the check
fails loudly if a future runner image drops it instead of quietly
linting less.
2026-07-28 12:46:17 -04:00
..
callable-dependency-review.yaml ci(dependency-review): add optional allow-ghsas pass-through input (#89) 2026-07-27 13:35:47 -04:00
callable-labeler.yaml Bump actions/labeler from 6.2.0 to 7.0.0 (#91) 2026-07-27 14:08:27 -04:00
cd-cdk.yaml ci: enable actionlint's shellcheck integration in self-CI 2026-07-28 12:46:17 -04:00
cd-dotnet-eb.yaml ci(cd-dotnet-eb): add reusable CD workflow for .NET on Elastic Beanstalk 2026-07-27 17:25:23 -04:00
cd-mobile-ios.yaml Bump the minor-and-patch group with 3 updates (#90) 2026-07-27 13:53:57 -04:00
cd-sam.yaml ci: enable actionlint's shellcheck integration in self-CI 2026-07-28 12:46:17 -04:00
ci-dotnet.yaml ci: scope the three reusable CI workflows to contents:read 2026-07-28 12:13:07 -04:00
ci-python-app.yaml fix: pin ruff to 0.15.22 in ci-python-sam and ci-python-app workflows (#88) 2026-07-23 15:51:07 -04:00
ci-python-sam.yaml ci: enable actionlint's shellcheck integration in self-CI 2026-07-28 12:46:17 -04:00
ci-static.yaml ci: pin workflow-template refs to commit SHA 2026-07-27 15:38:18 -04:00
ci-typescript-cdk.yaml ci: scope the three reusable CI workflows to contents:read 2026-07-28 12:13:07 -04:00
ci-typescript-frontend.yaml ci: pin workflow-template refs to commit SHA 2026-07-27 15:38:18 -04:00
ci.yaml ci: enable actionlint's shellcheck integration in self-CI 2026-07-28 12:46:17 -04:00
compliance-audit.yaml Bump the minor-and-patch group with 3 updates (#90) 2026-07-27 13:53:57 -04:00
labeler.yaml Run the org PR labeler on .github's own PRs 2026-06-16 15:51:10 -04:00