Skip to content

chore(ci): lint workflows with jactionlint - #244

Merged
jdx merged 2 commits into
mainfrom
chore/jactionlint
Oct 8, 2026
Merged

jdx merged 2 commits into
mainfrom
chore/jactionlint

Conversation

@jdx

@jdx jdx commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

https://entire.io/gh/jdx/demand/trails/25

Adds a jactionlint step to hk.pkl so workflow files are linted locally and in the hk pre-commit hook with jactionlint, a maintained actionlint fork. It catches bad inputs, expression type errors, script injection and unknown runner labels. jactionlint is added to mise.toml tools.

mise.lock is committed but did not list jactionlint, so this also locks it (mise lock jactionlint, v1.8.2, all 7 platforms already in the lockfile). CI already runs hk check --all in the test job, so the new step is exercised there with no workflow change.

Existing findings: none. All three workflows pass, so nothing was fixed or ignored.

Verified with hk check --all --step jactionlint (exit 0), and by adding an unknown key under on: in a workflow, which exited 1 before I reverted it.

🤖 Generated with Claude Code

AI-assisted — Tool: Claude Code; model: anthropic/claude-sonnet-5-5; version: claude-code_2-1-293_agent.


Note

Low Risk
Tooling and workflow lint configuration only; no application or runtime behavior changes.

Overview
Adds jactionlint to the shared hk linter set so .github/workflows/*.yml and *.yaml are validated on hk check, hk fix, and pre-commit alongside existing Rust linters.

The new step is check-only (jactionlint {{ files }}, read-only, batched). mise now installs jactionlint (latest in mise.toml, pinned to v1.8.2 across platforms in mise.lock).

Reviewed by Cursor Bugbot for commit bf62ce0. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • Chores
    • Updated the configured version of jactionlint to the latest release.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Central YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4566b4ce-ecc5-46d5-ac78-c3659d0c0314
📥 Commits

Reviewing files that changed from the base of the PR and between ef8f80d and d4b3c61.

⛔ Files ignored due to path filters (1)
  • hk.pkl is excluded by !**/*.pkl
📒 Files selected for processing (1)
  • mise.toml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The tools configuration adds jactionlint at the latest version.

Changes

Tooling

Layer / File(s) Summary
Add jactionlint to tools
mise.toml
The tools list adds jactionlint at the latest version.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to d4b3c

No actionable merge-blocking risk is established for the tool configuration change; normal checks can proceed.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding jactionlint to lint CI workflow files.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low impact] The PR appears safe to merge; the previous finding is fixed and no new actionable issues remain.

Summary

Adds jactionlint to the shared hk hooks to check GitHub Actions workflows.

  • Declares the tool in mise.toml.
  • Locks version 1.8.2 with checksums for seven platforms.
  • Fixes the previous finding about lint results drifting. No new actionable issues were found.

Reviews (2) · Last reviewed commit: "chore: lock jactionlint" · Reviewed by Greptile

Comment thread mise.toml

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit d4b3c61. Configure here.

Comment thread mise.toml
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jdx
jdx merged commit d3c8821 into main Oct 8, 2026
11 checks passed
@jdx
jdx deleted the chore/jactionlint branch October 8, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant