diff --git a/.github/workflows/lint-github-actions.yml b/.github/workflows/lint-github-actions.yml deleted file mode 100644 index 8413d8d..0000000 --- a/.github/workflows/lint-github-actions.yml +++ /dev/null @@ -1,35 +0,0 @@ -name: 🔍 Lint GitHub Actions - -on: - push: - branches: - - main - - beta - paths: - - ".github/workflows/**/*.yml" - - ".github/workflows/**/*.yaml" - pull_request: - paths: - - ".github/workflows/**/*.yml" - - ".github/workflows/**/*.yaml" - workflow_dispatch: {} - -permissions: {} - -jobs: - lint-github-actions: - name: 🔍 Lint GitHub Actions - runs-on: ubuntu-latest - permissions: - contents: read - - steps: - - name: 📥 Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: 🌈 Run zizmor - uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 - with: - advanced-security: false diff --git a/.github/workflows/lint-secrets.yml b/.github/workflows/lint-secrets.yml deleted file mode 100644 index 982f082..0000000 --- a/.github/workflows/lint-secrets.yml +++ /dev/null @@ -1,39 +0,0 @@ -name: 🔍 Lint Secrets - -on: - push: - branches: - - main - - beta - pull_request: {} - workflow_dispatch: {} - -permissions: {} - -jobs: - lint-secrets: - name: 🔍 Lint Secrets - runs-on: ubuntu-latest - permissions: - contents: read - - steps: - - name: 📥 Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: 🔍 Run secretlint - shell: bash - run: | - set -euo pipefail - - secretlint_version="$(node -p "require('./package.json').devDependencies.secretlint")" - secretlint_version="${secretlint_version#^}" - secretlint_version="${secretlint_version#~}" - secretlint_version="${secretlint_version#v}" - - docker run --rm --network none \ - -v "${PWD}:${PWD}" -w "${PWD}" \ - "secretlint/secretlint:v${secretlint_version}" \ - secretlint --format github "**/*" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 6e30691..ab8eb22 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -16,7 +16,6 @@ jobs: runs-on: ubuntu-latest if: ${{ !contains(github.event.head_commit.message, '[skip ci]') }} permissions: - actions: write contents: read concurrency: @@ -29,6 +28,32 @@ jobs: with: persist-credentials: false + # Linters run in the background while dependencies are installed. + # Uses the runner's preinstalled Node.js to read the secretlint version. + - name: 🔍 Lint secrets + id: lint-secrets + background: true + shell: bash + run: | + set -euo pipefail + + secretlint_version="$(node -p "require('./package.json').devDependencies.secretlint")" + secretlint_version="${secretlint_version#^}" + secretlint_version="${secretlint_version#~}" + secretlint_version="${secretlint_version#v}" + + docker run --rm --network none \ + -v "${PWD}:${PWD}" -w "${PWD}" \ + "secretlint/secretlint:v${secretlint_version}" \ + secretlint --format github "**/*" + + - name: 🌈 Lint GitHub Actions + id: lint-github-actions + background: true + uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + with: + advanced-security: false + - name: 🟢 Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -67,3 +92,7 @@ jobs: CI: true run: | npm test + + # Background step failures are only reported at a wait step + - name: ⏳ Wait for linters + wait: [lint-secrets, lint-github-actions]