Skip to content

ci: actionlint + concurrency harden (#41) - #44

Merged
CodeSolutionsLLC merged 2 commits into
mainfrom
ci/41-public-ci-harden
Sep 27, 2026
Merged

CodeSolutionsLLC merged 2 commits into
mainfrom
ci/41-public-ci-harden

Conversation

@CodeSolutionsLLC

@CodeSolutionsLLC CodeSolutionsLLC commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Thanks for the pull request. See CONTRIBUTING.md for how changes land on main.

Summary

Optional public CI harden from #41 (parent #35): fail-hard workflow lint with pinned actionlint, and cancel-in-progress concurrency on validate and CodeQL.

Related issue

Closes #41

Acceptance evidence

  • Workflow lint sibling job. .github/workflows/validate.yml keeps the existing job display name Markdown structure and adds sibling job workflow-lint (Workflow lint). It checks out with actions/checkout@v7, installs actionlint from the official release tarball (not a third-party Action), and runs ./actionlint -color .github/workflows/*.yml. Lint errors fail the job (timeout-minutes: 10, no continue-on-error).
  • actionlint pin. Version v1.7.12 (latest stable rhysd/actionlint release, not a prerelease). linux/amd64 tarball actionlint_1.7.12_linux_amd64.tar.gz. SHA256 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8, taken from the linux_amd64 line of the release checksums file actionlint_1.7.12_checksums.txt (https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_checksums.txt). That line matches the GitHub release asset digest. The job downloads the tarball and checksums with curl -fsSL, requires the pinned hash to appear in the checksums file, then sha256sum -c before extract.
  • Concurrency. The same block is on validate and CodeQL:
    concurrency:
      group: ${{ github.workflow }}-${{ github.ref }}
      cancel-in-progress: true
    CodeQL languages, permissions, job name Analyze, and github/codeql-action/*@v3 tags are unchanged. Actions stay on major tags (no full SHA-pin).
  • gitleaks skipped. Not added. This public tip repo should take on fewer third-party Actions. GitHub secret scanning and push protection already cover that surface.
  • Permissions. validate stays contents: read at workflow level. Workflow lint sets no job permissions, so it inherits contents: read only. CodeQL keeps contents: read, security-events: write, and actions: read. No extra secrets; checkout uses the default GITHUB_TOKEN.
  • Zero DENY items. No private reusable workflows, syncers, PAT-health, CIS/SOC2/ISO scanners, pull_request_target, fail-open gates, cross-repo checkout, seat/roster/bot vocabulary in Actions names, Soft pull of starship-*, or secrets beyond GITHUB_TOKEN. Paths touched: .github/workflows/validate.yml and .github/workflows/codeql.yml only.

How to verify

  • Confirm the diff is only those two workflow files.
  • Locally (optional): download actionlint_1.7.12_linux_amd64.tar.gz, check sha256 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 against actionlint_1.7.12_checksums.txt, then ./actionlint -color .github/workflows/*.yml.
  • On this PR, required check Markdown structure should stay green, and new check Workflow lint should pass with no lint errors. CodeQL Analyze should still run. Do not merge; human review only.
  • CI on f960c990c36174449892787091fb4f7fc44291ae: Markdown structure success, Workflow lint success (actionlint_1.7.12_linux_amd64.tar.gz: OK, version 1.7.12), Analyze (actions) success.

Checklist

  • Evidence recorded. Summary and how to verify are filled in (commands, tests, or links). See verify and playbooks/verify.md.
  • CI green. Required checks on this pull request are passing, including validate.
  • No secrets. The pull request body and diff have no tokens, PATs, private config, or exploit details. Report security issues privately — SECURITY.md.
  • CODEOWNERS human merge (no self-merge). Authors wait for an independent human review and merge. Reviewers are listed in .github/CODEOWNERS. See no-self-merge and human-gate.
  • Public language safe. No private credentials, internal roster names, or private links.
Open in Web Open in Cursor 

Add a fail-hard Workflow lint job that installs pinned actionlint v1.7.12
(linux/amd64 tarball, sha256 from the release checksums file) and cancel
in-progress runs on validate and CodeQL. Skip gitleaks.

Co-authored-by: Code Solutions LLC <CodeSolutionsLLC@users.noreply.github.com>

Copy link
Copy Markdown
Owner Author

Human VERIFY PASS (Computer)

Acceptance vs #41:

  • actionlint v1.7.12 pinned + sha256 verify; sibling Workflow lint; Markdown structure name unchanged
  • concurrency on validate + CodeQL
  • gitleaks skipped with public-safe reason
  • least-privilege permissions; paths = two workflow files only; zero DENY
  • CI green: Markdown structure, Workflow lint, Analyze, CodeQL

Note: mergeable_state=behind — update-branch before merge.
PR still draft — undraft as part of merge recipe.

Human HOLD invent Soft pull / CI bypass. Awaiting Code merge widget.

@CodeSolutionsLLC
CodeSolutionsLLC merged commit 933841b into main Sep 27, 2026
4 checks passed
@CodeSolutionsLLC
CodeSolutionsLLC deleted the ci/41-public-ci-harden branch September 27, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FTUE: optional public CI harden — actionlint + concurrency (+ optional gitleaks)

2 participants