Skip to content

chore(ci): add actionlint + yamllint workflow validation (#1513) - #1693

Open
Mossad-esc wants to merge 1 commit into
crackedstudio:masterfrom
Mossad-esc:chore/actionlint-workflow-validation
Open

Mossad-esc wants to merge 1 commit into
crackedstudio:masterfrom
Mossad-esc:chore/actionlint-workflow-validation

Conversation

@Mossad-esc

Copy link
Copy Markdown

Closes #1513

Summary

Adds a CI gate that validates all .github/workflows/*.yml files on every
PR/push that touches them. Also fixes five pre-existing bugs in ci.yml
that the linter would have caught, and cleans up unpinned action refs in
e2e.yml and performance-test.yml.

New files

.yamllint.yml

  • key-duplicates: forbid-duplicated-merge-keys: true — catches the exact
    "two workflows concatenated" failure mode from the issue
  • line-length relaxed to 160 (warning only)
  • truthy rule allows the bare on: GitHub Actions trigger key

.github/workflows/workflow-validation.yml

  • Triggers on PR/push when .github/workflows/** or .yamllint.yml change
  • yamllint 1.37.0 → shellcheck 0.10.0 → actionlint 1.7.7 (-shellcheck flag)
  • All three tools pinned to exact versions

.pre-commit-config.yaml

  • Local hook alternative per the issue; same pinned versions

Bugs fixed

ci.yml (5 bugs):

  • oracle paths-filter mis-indented — items fell under compose: not oracle:;
    oracle CI job never triggered on oracle file changes
  • database paths-filter was a sibling of filters: not nested inside it
  • "Check bundle size budgets" step duplicated 3× in the sdk job
  • verify-clean-tree used pnpm 8 / node 20 instead of 9.15.9 / .nvmrc
  • ci-summary referenced needs.compose-smoke.result but compose-smoke was
    absent from its needs array

e2e.yml: unpinned @v4 refs → SHA-pinned

performance-test.yml: all refs SHA-pinned; docker-compose → docker compose

…io#1513)

Add a CI gate that validates all .github/workflows/*.yml files on every
PR/push that touches them.  Also fix five pre-existing bugs in ci.yml
and clean up unpinned action refs in e2e.yml and performance-test.yml
that the new linter would have caught.

## New files

.yamllint.yml
- extends yamllint 'default' profile
- key-duplicates.forbid-duplicated-merge-keys: true  ← catches the
  'two workflows concatenated into one file' failure mode from the issue
- line-length relaxed to 160 (warning only)
- truthy rule allows bare 'on:' used by GitHub Actions trigger key
- comments min-spaces-from-content: 1 to allow SHA-pin inline comments

.github/workflows/workflow-validation.yml
- triggers on PR/push when .github/workflows/** or .yamllint.yml change
- step 1: yamllint 1.37.0 (duplicate-key detection, structural YAML)
- step 2: shellcheck 0.10.0 (installed so actionlint can call it)
- step 3: actionlint 1.7.7 with -shellcheck flag
  validates workflow syntax, expression syntax, and action input names
- all three tools pinned to exact versions

.pre-commit-config.yaml
- local hook alternative (per issue acceptance criteria)
- yamllint v1.37.0 hook scoped to .github/workflows/
- actionlint v1.7.7 hook with -shellcheck arg

## Bugs fixed in existing workflows

ci.yml — 5 bugs:
- oracle paths-filter block was mis-indented (items fell under compose:
  instead of oracle:); oracle CI job never triggered on oracle changes
- database paths-filter was a sibling of filters: not nested inside it;
  database output was always empty
- 'Check bundle size budgets' step duplicated 3x in sdk job (exact
  failure mode described in crackedstudio#1513 — duplicate keys silently drop jobs)
- verify-clean-tree used hardcoded pnpm 8 / node 20 instead of 9.15.9 /
  .nvmrc, inconsistent with every other job
- ci-summary referenced needs.compose-smoke.result but compose-smoke was
  not listed in its needs array

e2e.yml:
- unpinned actions/checkout@v4, actions/setup-node@v4,
  actions/upload-artifact@v4 replaced with SHA-pinned refs

performance-test.yml:
- all action refs pinned to SHAs
- docker-compose (deprecated standalone binary) → docker compose (plugin)

Closes crackedstudio#1513
@Mossad-esc
Mossad-esc requested a review from Otaiki1 as a code owner September 25, 2026 21:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[repo] Add actionlint so hand-edited workflows are validated

1 participant