Add CI for the shared workflows - #3
Merged
Merged
Conversation
This repo has no tests and nothing to build, but a mistake here breaks all three sites at once, and a workflow that fails to load reports only `startup_failure` with no logs and nothing on the annotations endpoint. Finding one of those cost a five-cycle bisection. So the checks target the failure modes that actually happened: - **actionlint**, which validates expressions against real context types and runs shellcheck over every `run:` block. It earned its place before being installed: it flagged `github.job_workflow_sha` as undefined, which five production runs then confirmed resolves to an empty string — a pin that was not pinning anything. And the worst bugs in these workflows have been shell rather than YAML: a `|| true` that swallowed an exit code and emailed an error body as a link, and a heredoc that fed one line to the interpreter. - **`node --check`** on the shared script, which is fetched and run at runtime, so a syntax error in it surfaces as a failed notification. - **A declared-inputs check**, since a `workflow_call` input used but never declared parses fine and arrives empty — the same silent class as the pin bug. Verified it fails on an undeclared input and an undeclared secret. The comments say what actionlint does *not* catch, so nobody assumes more of it than it gives: `vars.X` in a called workflow and `runner.temp` in a `with:` block both lint clean and both cost a cycle. `.github/actionlint.yaml` suppresses one style-only shellcheck rule with the reason recorded. Everything that could be a real bug stays on, which is why this currently exits non-zero on the `job_workflow_sha` line — so the pin fix must land first, rather than CI going red on its first run for a pre-existing issue.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repo has no tests and nothing to build, but a mistake here breaks all three sites at once — and a workflow that fails to load reports only
startup_failure, with no logs and nothing on the annotations endpoint. Finding one of those cost a five-cycle bisection.So the checks target the failure modes that actually happened here.
actionlint
It earned its place before being installed: it caught
github.job_workflow_shaas an undefined property — a bug already shipped and documented as a fix, which five production runs then confirmed resolved to an empty string. Fixed in #2.It also runs shellcheck over every
run:block, which matters because the worst bugs in these workflows have been shell rather than YAML:|| truethat swallowed an exit code and emailedgh's error body in place of a linkWhat it does not catch, recorded in the comments so nobody assumes more of it: semantic
workflow_callrules.vars.Xbeing unavailable in a called workflow, andrunner.tempin awith:block, both lint clean and both cost a bisection cycle.The other two checks
node --checkon the shared script, which is fetched and executed at runtime — so a syntax error there surfaces as a failed notification, not a parse error.workflow_callinput used but never declared parses fine and arrives empty, the same silent class as the pin bug. Verified it fails on an undeclared input and an undeclared secret, and anchored on^ workflow_call:so a mention in a comment does not count.Green on arrival
actionlint exits 0 on this branch now that #2 has landed. That ordering was deliberate — shipping a check that is already failing is how checks get ignored, which is the mistake made with the MDX check earlier.
.github/actionlint.yaml(already onmain) suppresses one style-only shellcheck rule with its reason recorded. Anything that could be a real bug stays on.After merging
Add
cias a required status check on this repo's ruleset, matchingpost-inbox. The context is the bare job id —ci, notci / ci— because this job is inline rather than a reusable workflow.🤖 Generated with Claude Code