Repository navigation
62 lines (54 loc) · 1.82 KB
/
Copy pathscripts-checks.yaml
File metadata and controls
62 lines (54 loc) · 1.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
name: Differential ShellCheck
on:
push:
paths:
- '**.sh'
- '.github/workflows/scripts-checks.yaml'
- 'tests/e2e/**'
branches:
- main
- 'release-[0-9]+.[0-9]+'
pull_request:
branches:
- main
- 'release-[0-9]+.[0-9]+'
concurrency:
group: ${{ github.workflow }}-${{ github.event.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
shellcheck-lint:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- name: Repository checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
# Differential ShellCheck requires full git history
fetch-depth: 0
persist-credentials: false # Critical: Do not store GITHUB_TOKEN in .git/config
- name: Get changed files
if: github.event_name == 'pull_request'
id: changed-files
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
files: |
**.sh
.github/workflows/scripts-checks.yaml
tests/e2e/**
- id: ShellCheck
if: github.event_name != 'pull_request' || steps.changed-files.outputs.any_changed == 'true'
name: Differential ShellCheck
uses: redhat-plumbers-in-action/differential-shellcheck@f51c7c0d32777d00de777131d25918617a246415 # v5
with:
token: ${{ secrets.GITHUB_TOKEN }}
exclude-path: ""
- if: always() && steps.ShellCheck.outcome != 'skipped'
name: Upload artifact with ShellCheck defects in SARIF format
uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7
with:
name: Differential ShellCheck SARIF
path: ${{ steps.ShellCheck.outputs.sarif }}