22# SPDX-License-Identifier: MIT
33name : Config validation
44
5- # The bot configs are the one part of CI that nothing else exercises: a broken
6- # renovate.json or dependabot.yml does not fail a build, it just quietly stops
7- # doing its job. This workflow is the thing that notices .
5+ # De bot- configs zijn het enige deel van CI dat verder nergens door wordt
6+ # geraakt: een kapotte renovate.json of dependabot.yml laat geen build falen,
7+ # die houdt gewoon stilletjes op met zijn werk. Deze workflow merkt dat op .
88
99on :
1010 push :
@@ -50,33 +50,33 @@ jobs:
5050 with :
5151 node-version : ' lts/*'
5252
53- # Renovate's own validator. --strict also fails on warnings, such as an
54- # option that is valid but deprecated. Given no arguments it finds the
55- # config files itself and validates them as repository config; passing a
56- # path instead makes it validate them as global config, which is a
57- # different and weaker set of rules .
53+ # Renovates eigen validator. --strict laat hem ook falen op warnings,
54+ # bijvoorbeeld een optie die geldig maar verouderd is. Zonder argumenten
55+ # zoekt hij de configbestanden zelf op en valideert hij ze als
56+ # repository-config; geef je een pad mee, dan valideert hij ze als
57+ # global config, en dat is een andere en zwakkere set regels .
5858 #
59- # Deliberately unpinned. This is a linter for our config, not something we
60- # ship, and the newest release is the one that knows about the newest
61- # deprecations. Its own version is not worth a pull request.
59+ # Bewust niet vastgezet. Dit is een linter op onze eigen config en geen
60+ # onderdeel van wat we uitleveren, en juist de nieuwste release kent de
61+ # nieuwste deprecations. Zijn eigen versie is geen pull request waard .
6262 #
63- # NPM_CONFIG_LOGLEVEL: npm prints "npm warn deprecated ..." for packages
64- # deep inside Renovate's own dependency tree. Those say nothing about the
65- # config being validated, and reading them as if they did is the obvious
66- # mistake to make when they appear directly above the validator's output .
63+ # NPM_CONFIG_LOGLEVEL: npm print "npm warn deprecated ..." voor packages
64+ # diep in Renovates eigen dependency-boom. Die zeggen niets over de config
65+ # die gevalideerd wordt, en ze lezen alsof dat wel zo is, is de fout die
66+ # je vanzelf maakt als ze vlak boven de output van de validator staan .
6767 - name : Validate Renovate config
6868 env :
6969 NPM_CONFIG_LOGLEVEL : error
7070 run : npx --yes --package renovate -- renovate-config-validator --strict
7171
72- # The validator above accepts a well-formed pattern that matches nothing,
73- # so this covers the gap it leaves .
72+ # De validator hierboven accepteert een correct gevormd patroon dat
73+ # nergens op matcht; dit dekt het gat dat hij daarmee laat .
7474 - name : Check Renovate file patterns
7575 run : python3 .github/scripts/check-renovate-patterns.py renovate.json .github/renovate.json
7676
77- # GitHub validates dependabot.yml only after it is on the default branch,
78- # and reports the result on a tab nobody opens. This brings that forward
79- # to the pull request.
77+ # GitHub valideert dependabot.yml pas als die op de default branch staat ,
78+ # en meldt het resultaat op een tabblad dat niemand opent. Dit haalt dat
79+ # naar voren, naar de pull request.
8080 - name : Validate Dependabot config
8181 env :
8282 # renovate: datasource=pypi depName=check-jsonschema
@@ -96,23 +96,19 @@ jobs:
9696 pipx install "check-jsonschema==${CHECK_JSONSCHEMA_VERSION}"
9797 check-jsonschema --builtin-schema vendor.dependabot "$config"
9898
99- # The workflow files are config too. The other repositories in the
100- # organisation run actionlint from their quality workflow; this one had no
101- # equivalent, so it lives here.
102- workflow-lint :
103- name : Check workflow files
104- runs-on : ubuntu-latest
105- permissions :
106- contents : read
107- steps :
108- - name : Check out source code
109- uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
110- with :
111- persist-credentials : false
112-
113- # Pinned release plus checksum, rather than piping a script from a
114- # branch straight into bash.
99+ # De workflowbestanden zijn ook config. De andere repositories draaien
100+ # actionlint vanuit hun quality-workflow; deze had geen equivalent, dus
101+ # het hoort hier.
102+ #
103+ # Als stap en niet als eigen job: GitHub rekent per job en rondt naar
104+ # boven af op een hele minuut. actionlint is in vijf seconden klaar en
105+ # heeft dezelfde checkout nodig als de stappen hierboven, dus een eigen
106+ # job kostte een volle minuut extra voor niets.
107+ #
108+ # Vanaf hier draait elke stap op !cancelled(), zodat één rode controle de
109+ # andere niet verbergt. De job faalt alsnog zodra er iets fout is.
115110 - name : Install actionlint
111+ if : ${{ !cancelled() }}
116112 env :
117113 # renovate: datasource=github-releases depName=rhysd/actionlint
118114 ACTIONLINT_VERSION : " 1.7.12"
@@ -126,4 +122,5 @@ jobs:
126122 sudo install -m 0755 actionlint /usr/local/bin/actionlint
127123
128124 - name : Run actionlint
125+ if : ${{ !cancelled() }}
129126 run : actionlint -color
0 commit comments