mirror of
https://github.com/Sea-Haven-Industries/shoc-pr-review-runner.git
synced 2026-10-02 07:03:11 +00:00
The org main-branch ruleset requires the status context `ci / ci`. A job defined directly in a workflow emits only its job name, so this repo's CI published `ci` and could never satisfy that rule. The two-part context comes from a reusable-workflow call, named `<caller job> / <called job>`. Move the checks into a local reusable and leave ci.yaml as a thin caller, which is also the structural convention the org reusables follow. No org reusable fits a bash and workflow tooling repo, so the reusable lives here.
79 lines
3 KiB
YAML
79 lines
3 KiB
YAML
name: CI — Runner Checks
|
|
|
|
# Reusable CI for this repository's own shell/workflow tooling. Kept as a
|
|
# reusable (rather than inlining the steps in ci.yaml) so the caller emits the
|
|
# two-part `ci / ci` status context the org "main branch protection" ruleset
|
|
# requires. None of the org reusables fit a bash + workflow tooling repo:
|
|
# ci-static validates HTML, ci-typescript-* and ci-python-* expect a package
|
|
# manifest, ci-dotnet expects a solution. This repo has none of those.
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
actionlint-version:
|
|
description: actionlint release to download
|
|
type: string
|
|
default: "1.7.12"
|
|
actionlint-sha256:
|
|
description: sha256 of the actionlint linux_amd64 tarball
|
|
type: string
|
|
default: "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8"
|
|
check-jsonschema-version:
|
|
description: pinned check-jsonschema version
|
|
type: string
|
|
default: "0.37.4"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ci:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
concurrency:
|
|
group: ci-runner-checks-${{ github.workflow }}-${{ github.job }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: shellcheck all scripts
|
|
run: |
|
|
shopt -s nullglob
|
|
files=(scripts/*.sh tests/*.sh)
|
|
echo "checking: ${files[*]}"
|
|
shellcheck --external-sources --source-path=scripts "${files[@]}"
|
|
|
|
- name: actionlint all workflows
|
|
env:
|
|
ACTIONLINT_VERSION: ${{ inputs.actionlint-version }}
|
|
ACTIONLINT_SHA256: ${{ inputs.actionlint-sha256 }}
|
|
run: |
|
|
curl -sSfL -o actionlint.tar.gz \
|
|
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
|
|
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c -
|
|
tar -xzf actionlint.tar.gz actionlint
|
|
./actionlint -color
|
|
|
|
- name: validate input schema + fixtures
|
|
env:
|
|
CHECK_JSONSCHEMA_VERSION: ${{ inputs.check-jsonschema-version }}
|
|
run: |
|
|
# Pinned: the same integrity bar the actionlint download above meets.
|
|
python3 -m pip install --quiet "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}"
|
|
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
|
|
for f in tests/fixtures/inputs/valid-*.json; do
|
|
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
|
|
done
|
|
for f in tests/fixtures/inputs/invalid-*.json; do
|
|
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
|
|
echo "expected $f to FAIL schema validation" >&2; exit 1
|
|
fi
|
|
done
|
|
|
|
- name: bash tests
|
|
run: |
|
|
./tests/test-input-validation.sh
|
|
./tests/test-output-validation.sh
|
|
./tests/test-gate-integrity.sh
|