ascheman opened a new pull request, #322: URL: https://github.com/apache/maven-gh-actions-shared/pull/322
Adds a reusable workflow (`on: workflow_call`) that lints a repository's own GitHub Actions workflows with [actionlint](https://github.com/rhysd/actionlint) — workflow syntax, expression contexts, and embedded shell (via shellcheck). **Why super-linter and not the stand-alone actionlint action:** the ASF org allowed-actions policy permits GitHub-owned actions (`github/super-linter` is GitHub-owned) but not the stand-alone `rhysd/actionlint` action or its `docker://` image. super-linter is run restricted to the GitHub Actions validator (`VALIDATE_GITHUB_ACTIONS`). Consumers add a one-line caller in `.github/workflows/actionlint.yml`: ```yaml name: Actionlint on: push: paths: [ '.github/workflows/**' ] pull_request: paths: [ '.github/workflows/**' ] jobs: actionlint: uses: apache/maven-gh-actions-shared/.github/workflows/actionlint.yml@v5 ``` Optional input `validate-all-codebase` (default `true`) lints every workflow file; `false` lints only the event's changed files. README updated with usage. Validated end-to-end on a fork (super-linter `slim-v7.1.0`, actionlint 1.7.1) — the workflow runs and correctly reports findings. Companion: apache/maven will adopt this via a thin caller (replacing the standalone apache/maven#13083). A follow-up will add a self-lint caller here plus the few shellcheck fixes actionlint surfaces in the existing workflows. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01SzYpt848HdNm1xVA4vBR3F -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
