The gap
actionlint is treated as a standard for this repo — the versioned-Pages plan
(#464) lists "actionlint must be clean on every workflow file" as a global
constraint, and every workflow added there was linted by hand before it landed.
But nothing runs it. lint.yml gates on zizmor (lint.yml:29-43),
shellcheck (:15-27), SwiftFormat and SwiftLint — not actionlint. Neither
does the .githooks/ pre-commit hook. The standard has held so far purely
because whoever touched a workflow remembered to run it locally, which is not a
gate, and will stop holding the first time someone doesn't.
Why it can't just be switched on
Repo-wide, actionlint currently exits 1 on two pre-existing findings, so
adding the step to lint.yml today turns the shell job — a required check —
red immediately. Both need fixing first.
1. test-artifacts.yml:46 — undefined matrix property (real, not style)
property "macos_version" is not defined in object type {xcode_version: string}
name: sample-test-results-${{ matrix.macos_version }}-${{ matrix.xcode_version }}
The matrix declares only xcode_version; macos_version was commented out
(test-artifacts.yml:17-24) but the reference at line 46 survived. The
expression resolves to empty, so uploaded artifacts are named
sample-test-results--latest-stable and sample-test-results--15 — a stray
double hyphen where the OS should be.
Low blast radius (the workflow is workflow_dispatch-only and the two names
still differ, so nothing collides), but it is a genuine defect and exactly the
class of thing actionlint exists to catch.
Fix: drop ${{ matrix.macos_version }}- from the name, or restore the matrix
dimension.
2. release.yml:132 — SC2129 (style)
shellcheck reported issue in this script: SC2129:style:1:1:
Consider using { cmd1; cmd2; } >> file instead of individual redirects
Pure style, surfaced because actionlint runs shellcheck over run: blocks.
Either group the redirects or scope a disable with a comment.
Proposed
- Fix the two findings above.
- Add an
actionlint step to lint.yml's existing ubuntu actions job — it
already exists for zizmor, so this needs no new job and no new runner.
Worth doing as one change: the fixes are only worth making if the gate follows,
and the gate can't land until they do.
Found during the final review of #464. The versioned-Pages work itself is
actionlint-clean on every file it touched — this is about the surrounding repo
and about making the standard enforced rather than remembered.
The gap
actionlintis treated as a standard for this repo — the versioned-Pages plan(#464) lists "actionlint must be clean on every workflow file" as a global
constraint, and every workflow added there was linted by hand before it landed.
But nothing runs it.
lint.ymlgates onzizmor(lint.yml:29-43),shellcheck(:15-27), SwiftFormat and SwiftLint — notactionlint. Neitherdoes the
.githooks/pre-commit hook. The standard has held so far purelybecause whoever touched a workflow remembered to run it locally, which is not a
gate, and will stop holding the first time someone doesn't.
Why it can't just be switched on
Repo-wide,
actionlintcurrently exits 1 on two pre-existing findings, soadding the step to
lint.ymltoday turns theshelljob — a required check —red immediately. Both need fixing first.
1.
test-artifacts.yml:46— undefined matrix property (real, not style)The matrix declares only
xcode_version;macos_versionwas commented out(
test-artifacts.yml:17-24) but the reference at line 46 survived. Theexpression resolves to empty, so uploaded artifacts are named
sample-test-results--latest-stableandsample-test-results--15— a straydouble hyphen where the OS should be.
Low blast radius (the workflow is
workflow_dispatch-only and the two namesstill differ, so nothing collides), but it is a genuine defect and exactly the
class of thing actionlint exists to catch.
Fix: drop
${{ matrix.macos_version }}-from the name, or restore the matrixdimension.
2.
release.yml:132— SC2129 (style)Pure style, surfaced because actionlint runs shellcheck over
run:blocks.Either group the redirects or scope a disable with a comment.
Proposed
actionlintstep tolint.yml's existing ubuntuactionsjob — italready exists for
zizmor, so this needs no new job and no new runner.Worth doing as one change: the fixes are only worth making if the gate follows,
and the gate can't land until they do.
Found during the final review of #464. The versioned-Pages work itself is
actionlint-clean on every file it touched — this is about the surrounding repo
and about making the standard enforced rather than remembered.