Repository navigation
Lint shell, Python and Containerfiles on every PR - #15
Merged
Merged
Conversation
The repo had no CI, so nothing verified a PR before merge. A full Containerfile build would take tens of minutes and still cover almost none of the open diffs, so lint what the tree actually contains instead: shellcheck, ruff and hadolint, in parallel, in under a minute. Fixes the four pre-existing shellcheck warnings at source (two intentional SC2211 globs, three SC2034 retry counters) so the shell gate can sit at --severity=warning rather than the toothless error level. See docs/adr/0007.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repo had no CI at all — no workflows, no branch protection,
allow_auto_mergeoff — sogh pr checksreported "no checks reported" on every branch and nothing verified a PR before merge.What this adds
.github/workflows/lint.yml, three parallel jobs on every PR and on pushes tomaster:shellcheck--severity=warning*.shruffruff==0.11.7tools/hadolinthadolint:v2.15.1-alpineContainerfile.*Finishes in well under a minute.
Why not build the container
It would take tens of minutes per PR (stage 1 compiles qdomyos-zwift from source; stage 2 adds Wine, Mesa, DXVK, VKD3D and runs the TPV installer under Xvfb) — and it would cover almost none of the open diffs. #14 is pure Python plus docs; #8 is shell plus one line of
Containerfile.full. It would also re-fetch and execute the proprietary TPV installer from public CI on every run.A
workflow_dispatch+ scheduled real build is the intended follow-up, so breakage is caught on a timer instead of gating PRs.The shell fixes
Four pre-existing shellcheck warnings, all false positives, fixed at source so the gate can sit at
warninginstead of the toothlesserror:scripts/build-prefix.sh×2 — SC2211, deliberate globs (version dir unknown until build time, both already have a||fallback) →# shellcheck disable=SC2211tools/kernel-test-vm/*.sh×3 — SC2034, unused counter infor i in $(seq 1 90)→for _Reasoning in full:
docs/adr/0007-lint-only-ci-not-a-container-build.md.