Skip to content

ci: run actionlint + zizmor as a fail-closed workflow gate (.github/actionlint.yaml exists but nothing runs it) #3314

Description

@Xore

What

.github/actionlint.yaml is tracked, but no workflow invokes actionlint. #3282's PR body records actionlint: NOT RUN (binary not installed). Workflow YAML changes are validated only by yaml.safe_load, which catches no expression, needs:, shell or injection errors.

Proposal

A workflow-lint job in quality.yml, path-filtered to .github/**, but with a fixed aggregate so it always reports:

  • actionlint at a pinned version, which also shellchecks run: blocks, using the existing config.
  • zizmor at a pinned version for template-injection, persist-credentials and unpinned-uses findings. Start it advisory, then flip to blocking once the ci: finish checkout-credential and action-pin hardening across all workflows #3313 hardening lands.
  • Install both from checksummed release assets so the job doesn't depend on runner-image state.

Sources

Found by the #3194 OmniRoute ops/CI deep-check (pinned 18bbb101, APIARY main 3dca4457).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestin-progressActively being worked onopsDeployment, runners, observability, host access

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions