name: CI — Runner Checks # Reusable CI for this repository's own shell/workflow tooling. Kept as a # reusable (rather than inlining the steps in ci.yaml) so the caller emits the # two-part `ci / ci` status context the org "main branch protection" ruleset # requires. None of the org reusables fit a bash + workflow tooling repo: # ci-static validates HTML, ci-typescript-* and ci-python-* expect a package # manifest, ci-dotnet expects a solution. This repo has none of those. on: workflow_call: inputs: actionlint-version: description: actionlint release to download type: string default: "1.7.12" actionlint-sha256: description: sha256 of the actionlint linux_amd64 tarball type: string default: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8" check-jsonschema-version: description: pinned check-jsonschema version type: string default: "0.37.4" permissions: contents: read jobs: ci: runs-on: ubuntu-latest timeout-minutes: 15 concurrency: group: ci-runner-checks-${{ github.workflow }}-${{ github.job }}-${{ github.ref }} cancel-in-progress: true steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: shellcheck all scripts run: | shopt -s nullglob files=(scripts/*.sh tests/*.sh) echo "checking: ${files[*]}" shellcheck --external-sources --source-path=scripts "${files[@]}" - name: actionlint all workflows env: ACTIONLINT_VERSION: ${{ inputs.actionlint-version }} ACTIONLINT_SHA256: ${{ inputs.actionlint-sha256 }} run: | curl -sSfL -o actionlint.tar.gz \ "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c - tar -xzf actionlint.tar.gz actionlint ./actionlint -color - name: validate input schema + fixtures env: CHECK_JSONSCHEMA_VERSION: ${{ inputs.check-jsonschema-version }} run: | # Pinned: the same integrity bar the actionlint download above meets. python3 -m pip install --quiet "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}" check-jsonschema --check-metaschema review/schemas/review-input.schema.json for f in tests/fixtures/inputs/valid-*.json; do check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" done for f in tests/fixtures/inputs/invalid-*.json; do if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then echo "expected $f to FAIL schema validation" >&2; exit 1 fi done - name: bash tests run: | ./tests/test-input-validation.sh ./tests/test-output-validation.sh ./tests/test-gate-integrity.sh