chore: import upstream snapshot with attribution
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
This commit is contained in:
@@ -0,0 +1,81 @@
|
||||
name: ShellCheck
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
shellcheck:
|
||||
name: Lint shell scripts
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
||||
|
||||
- name: Install ShellCheck
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y shellcheck
|
||||
shellcheck --version
|
||||
|
||||
- name: Run ShellCheck on ods shell scripts
|
||||
run: |
|
||||
# Find all .sh files under ods/
|
||||
shfiles=$(find ods/ -name '*.sh' -type f)
|
||||
|
||||
if [ -z "$shfiles" ]; then
|
||||
echo "No .sh files found under ods/"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
echo "Found $(echo "$shfiles" | wc -l) shell scripts"
|
||||
echo ""
|
||||
|
||||
# Run shellcheck:
|
||||
# -e SC1091 exclude "can't follow sourced files"
|
||||
# -e SC2034 exclude "unused variables" (many are used by sourced files)
|
||||
# -S warning treat warnings and above as reportable
|
||||
# shellcheck returns:
|
||||
# 0 = no issues
|
||||
# 1 = errors or warnings found
|
||||
# We fail the job only on error-severity issues by using -S error,
|
||||
# but still display warnings for visibility.
|
||||
|
||||
# First pass: display all warnings and errors for visibility
|
||||
echo "=== ShellCheck results (warnings + errors) ==="
|
||||
echo "$shfiles" | xargs shellcheck \
|
||||
--exclude=SC1091,SC2034 \
|
||||
--severity=warning \
|
||||
--format=gcc \
|
||||
|| true
|
||||
|
||||
echo ""
|
||||
echo "=== Checking for error-severity issues (will fail if found) ==="
|
||||
|
||||
# Second pass: fail only on error severity
|
||||
echo "$shfiles" | xargs shellcheck \
|
||||
--exclude=SC1091,SC2034 \
|
||||
--severity=error
|
||||
|
||||
- name: Regression guard - no http://localhost in shell scripts
|
||||
run: |
|
||||
# IPv6 ::1 resolution can hang on macOS; always use 127.0.0.1 in
|
||||
# shell scripts. Excludes: demo-offline.sh (echo'd documentation,
|
||||
# never executed) and test-extension-audit.sh (heredoc compose YAML
|
||||
# fixtures with container-internal localhost).
|
||||
# Note: extensionless scripts (e.g. ods-cli) are not scanned by
|
||||
# this glob; coverage is limited to *.sh / *.bash. ods-cli's
|
||||
# localhost sites were handled by the earlier localhost-to-127.0.0.1 sweep.
|
||||
matches=$(find ods -type f \( -name '*.sh' -o -name '*.bash' \) \
|
||||
! -path 'ods/scripts/demo-offline.sh' \
|
||||
! -path 'ods/tests/test-extension-audit.sh' \
|
||||
-exec grep -nE 'curl[^|]*http://localhost:' {} + || true)
|
||||
if [ -n "$matches" ]; then
|
||||
echo "::error::curl http://localhost: detected; use 127.0.0.1 (IPv6 ::1 resolution can hang on macOS):"
|
||||
echo "$matches"
|
||||
exit 1
|
||||
fi
|
||||
Reference in New Issue
Block a user