Embed shared terminal interaction in the TUI #228
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Actionlint | |
| # Lints the workflows themselves: a typo in a job key, an expression that never | |
| # resolves, a `run:` step shellcheck would reject. These files gate every merge | |
| # and every release, and nothing else checks them -- a broken workflow is only | |
| # discovered by the run that fails, if it runs at all. | |
| # | |
| # Separate from ci.yml because it depends on none of the toolchain that one | |
| # installs: it lints the tree, not the code. Its own runs are seconds. | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| # Read-only. This job only inspects the tree. | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: actionlint-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| actionlint: | |
| runs-on: ubuntu-latest | |
| # Seconds of work. Ten minutes means something hung. | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| # The binary is fetched at a pinned version and verified against its | |
| # published SHA-256 before it runs -- the same guarantee a SHA-pinned | |
| # action gives, without taking on another third-party action to lint the | |
| # others. shellcheck is already on the runner; actionlint finds it and | |
| # runs it over every `run:` block. | |
| # | |
| # This curl is a DECISION, not an oversight. Dependabot cannot watch a | |
| # curl'd binary, and the fix that would make it watchable does not | |
| # exist: rhysd/actionlint has never shipped a GitHub Action -- no | |
| # action.yml exists at any tag back to v1.0.0, or anywhere in the | |
| # repository's commit history -- and upstream's own docs recommend this | |
| # same download-and-run recipe. Third-party wrapper actions exist, but | |
| # one of those would add a party to the trust path to gain the | |
| # dependabot entry. So the pin moves by hand, in lockstep across the | |
| # three ormos repos, and the sha256 line is what makes the moving tag | |
| # irrelevant. | |
| - name: Install actionlint | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| version=1.7.12 | |
| sha256=8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 | |
| url="https://github.com/rhysd/actionlint/releases/download/v${version}/actionlint_${version}_linux_amd64.tar.gz" | |
| curl --fail --silent --show-error --location "$url" -o actionlint.tar.gz | |
| echo "${sha256} actionlint.tar.gz" | sha256sum --check --strict - | |
| tar -xzf actionlint.tar.gz actionlint | |
| rm -f actionlint.tar.gz | |
| - name: Lint the workflows | |
| shell: bash | |
| run: ./actionlint -color |