name: ci # Repo-local CI for the runner itself. No org reusable fits a bash/workflow # tooling repo, so this thin workflow lints every script and workflow, validates # the input schema, and runs the bash test suite. The job is named `ci` so the # required status context is `ci / ci`, matching the org ruleset convention. on: pull_request: branches: [main] permissions: contents: read jobs: ci: runs-on: ubuntu-latest timeout-minutes: 15 concurrency: group: ci-${{ github.ref }} cancel-in-progress: true steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: shellcheck all scripts run: | shopt -s nullglob files=(scripts/*.sh tests/*.sh) echo "checking: ${files[*]}" shellcheck --external-sources --source-path=scripts "${files[@]}" - name: actionlint all workflows run: | curl -sSfL -o actionlint.tar.gz \ https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c - tar -xzf actionlint.tar.gz actionlint ./actionlint -color - name: validate input schema + fixtures run: | # Pinned: the same integrity bar the actionlint download above meets. python3 -m pip install --quiet 'check-jsonschema==0.37.4' check-jsonschema --check-metaschema review/schemas/review-input.schema.json for f in tests/fixtures/inputs/valid-*.json; do check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" done for f in tests/fixtures/inputs/invalid-*.json; do if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then echo "expected $f to FAIL schema validation" >&2; exit 1 fi done - name: bash tests run: | ./tests/test-input-validation.sh ./tests/test-output-validation.sh ./tests/test-gate-integrity.sh