mirror of
https://github.com/trailofbits/algo.git
synced 2026-09-28 12:35:00 +02:00
20e22a8715
Bumps the github-actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.1.0` | `4.2.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.2.0` | `4.4.0` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.1.0` | `6.2.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.3.0` | `7.0.0` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.2` | Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd87d3ba754cc423b652a5edd6d2c) Updates `docker/login-action` from 4.2.0 to 4.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...af1e73f918a031802d376d3c8bbc3fe56130a9b0) Updates `docker/metadata-action` from 6.1.0 to 6.2.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](https://github.com/docker/metadata-action/compare/80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9...dc802804100637a589fabce1cb79ff13a1411302) Updates `actions/setup-python` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b97) Updates `dorny/paths-filter` from 4.0.1 to 4.0.2 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](https://github.com/dorny/paths-filter/compare/fbd0ab8f3e69293af611ebaee6363fc25e6d187d...7b450fff21473bca461d4b92ce414b9d0420d706) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dorny/paths-filter dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
207 lines
6.2 KiB
YAML
207 lines
6.2 KiB
YAML
---
|
|
name: Lint
|
|
|
|
'on':
|
|
push:
|
|
branches: [main, master]
|
|
pull_request:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ansible-lint:
|
|
name: Ansible linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Algo environment
|
|
uses: ./.github/actions/setup-algo
|
|
with:
|
|
install-ansible-collections: 'true'
|
|
|
|
- name: Run ansible-lint
|
|
run: |
|
|
uv run --with ansible-lint ansible-lint .
|
|
|
|
- name: Run playbook dry-run check (catch runtime issues)
|
|
run: |
|
|
# Test main playbook logic without making changes
|
|
# This catches filter warnings, collection issues, and runtime errors
|
|
uv run ansible-playbook main.yml --check --connection=local \
|
|
-e "server_ip=test" \
|
|
-e "server_name=ci-test" \
|
|
-e "IP_subject_alt_name=192.168.1.1" \
|
|
|| echo "Dry-run check completed with issues - review output above"
|
|
|
|
yaml-lint:
|
|
name: YAML linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup uv environment
|
|
uses: ./.github/actions/setup-uv
|
|
|
|
- name: Run yamllint
|
|
run: uv run --with yamllint yamllint -c .yamllint .
|
|
|
|
jinja2-lint:
|
|
name: Jinja2 template linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup uv environment
|
|
uses: ./.github/actions/setup-uv
|
|
|
|
- name: Run j2lint
|
|
run: |
|
|
# Lint Jinja2 templates for syntax and style issues
|
|
# Ignored rules (incompatible with Ansible config-file templates):
|
|
# S3: indentation (dictated by output format, not Jinja style)
|
|
# S5: tabs (some config formats require them)
|
|
# S6: whitespace-control delimiters ({%- -%} are standard Ansible)
|
|
# S7: single-statement-per-line (inline Jinja in config output)
|
|
# V1: lowercase variables (existing names like IP_subject_alt_name)
|
|
uv run --with j2lint j2lint roles/ --ignore S3 S5 S6 S7 V1
|
|
|
|
python-lint:
|
|
name: Python linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Algo environment
|
|
uses: ./.github/actions/setup-algo
|
|
|
|
- name: Run ruff check
|
|
run: |
|
|
# Fast Python linter
|
|
uv run --with ruff ruff check .
|
|
|
|
- name: Run ruff format check
|
|
run: |
|
|
# Verify consistent Python formatting
|
|
uv run --with ruff ruff format --check .
|
|
|
|
python-types:
|
|
name: Python type checking
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Algo environment
|
|
uses: ./.github/actions/setup-algo
|
|
|
|
- name: Run ty check
|
|
run: |
|
|
# Type checking with ty
|
|
uv run --with ty ty check
|
|
|
|
shellcheck:
|
|
name: Shell script linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Algo environment
|
|
uses: ./.github/actions/setup-algo
|
|
with:
|
|
install-shellcheck: 'true'
|
|
|
|
- name: Run shellcheck
|
|
run: |
|
|
# Check all shell scripts, not just algo and install.sh
|
|
find . -type f -name "*.sh" -not -path "./.git/*" -exec shellcheck {} \;
|
|
|
|
powershell-lint:
|
|
name: PowerShell script linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install PowerShell
|
|
run: |
|
|
# Install PowerShell Core
|
|
wget -q https://github.com/PowerShell/PowerShell/releases/download/v7.4.0/powershell_7.4.0-1.deb_amd64.deb
|
|
sudo dpkg -i powershell_7.4.0-1.deb_amd64.deb
|
|
sudo apt-get install -f
|
|
|
|
- name: Install PSScriptAnalyzer
|
|
run: |
|
|
pwsh -Command "Install-Module -Name PSScriptAnalyzer -Force -Scope CurrentUser"
|
|
|
|
- name: Run PowerShell syntax check
|
|
run: |
|
|
# Check syntax by parsing the script
|
|
pwsh -NoProfile -NonInteractive -Command "
|
|
try {
|
|
\$null = [System.Management.Automation.PSParser]::Tokenize((Get-Content -Path './algo.ps1' -Raw), [ref]\$null)
|
|
Write-Host '✓ PowerShell syntax check passed'
|
|
} catch {
|
|
Write-Error 'PowerShell syntax error: ' + \$_.Exception.Message
|
|
exit 1
|
|
}
|
|
"
|
|
|
|
- name: Run PSScriptAnalyzer
|
|
run: |
|
|
pwsh -Command "
|
|
\$results = Invoke-ScriptAnalyzer -Path './algo.ps1' -Severity Warning,Error
|
|
if (\$results.Count -gt 0) {
|
|
\$results | Format-Table -AutoSize
|
|
exit 1
|
|
} else {
|
|
Write-Host '✓ PSScriptAnalyzer check passed'
|
|
}
|
|
"
|
|
|
|
actionlint:
|
|
name: GitHub Actions linting
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install actionlint
|
|
run: |
|
|
bash <(curl -sL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
|
|
sudo mv actionlint /usr/local/bin/
|
|
|
|
- name: Run actionlint
|
|
run: |
|
|
actionlint .github/workflows/*.yml
|
|
|
|
zizmor:
|
|
name: GitHub Actions security audit
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install zizmor
|
|
run: |
|
|
pip install zizmor
|
|
|
|
- name: Run zizmor
|
|
run: |
|
|
zizmor .github/workflows/
|