Repository navigation
ci: actionlint + concurrency harden (#41) - #44
Merged
Merged
Conversation
Add a fail-hard Workflow lint job that installs pinned actionlint v1.7.12 (linux/amd64 tarball, sha256 from the release checksums file) and cancel in-progress runs on validate and CodeQL. Skip gitleaks. Co-authored-by: Code Solutions LLC <CodeSolutionsLLC@users.noreply.github.com>
Owner
Author
Human VERIFY PASS (Computer)Acceptance vs #41:
Note: Human HOLD invent Soft pull / CI bypass. Awaiting Code merge widget. |
6 tasks
CodeSolutionsLLC
marked this pull request as ready for review
September 27, 2026 23:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thanks for the pull request. See CONTRIBUTING.md for how changes land on
main.Summary
Optional public CI harden from #41 (parent #35): fail-hard workflow lint with pinned actionlint, and cancel-in-progress concurrency on validate and CodeQL.
Related issue
Closes #41
Acceptance evidence
.github/workflows/validate.ymlkeeps the existing job display nameMarkdown structureand adds sibling jobworkflow-lint(Workflow lint). It checks out withactions/checkout@v7, installs actionlint from the official release tarball (not a third-party Action), and runs./actionlint -color .github/workflows/*.yml. Lint errors fail the job (timeout-minutes: 10, nocontinue-on-error).actionlint_1.7.12_linux_amd64.tar.gz. SHA2568aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8, taken from thelinux_amd64line of the release checksums fileactionlint_1.7.12_checksums.txt(https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_checksums.txt). That line matches the GitHub release asset digest. The job downloads the tarball and checksums withcurl -fsSL, requires the pinned hash to appear in the checksums file, thensha256sum -cbefore extract.validateandCodeQL:Analyze, andgithub/codeql-action/*@v3tags are unchanged. Actions stay on major tags (no full SHA-pin).validatestayscontents: readat workflow level.Workflow lintsets no job permissions, so it inheritscontents: readonly. CodeQL keepscontents: read,security-events: write, andactions: read. No extra secrets; checkout uses the defaultGITHUB_TOKEN.pull_request_target, fail-open gates, cross-repo checkout, seat/roster/bot vocabulary in Actions names, Soft pull of starship-*, or secrets beyondGITHUB_TOKEN. Paths touched:.github/workflows/validate.ymland.github/workflows/codeql.ymlonly.How to verify
actionlint_1.7.12_linux_amd64.tar.gz, check sha2568aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8againstactionlint_1.7.12_checksums.txt, then./actionlint -color .github/workflows/*.yml.f960c990c36174449892787091fb4f7fc44291ae: Markdown structure success, Workflow lint success (actionlint_1.7.12_linux_amd64.tar.gz: OK, version1.7.12), Analyze (actions) success.Checklist