-
-
Notifications
You must be signed in to change notification settings - Fork 20
88 lines (78 loc) · 4.17 KB
/
Copy pathlinter.yml
File metadata and controls
88 lines (78 loc) · 4.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
name: Lint Code Base
on: pull_request
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# super-linter reports results as commit statuses, and reads nothing else.
permissions:
contents: read
statuses: write
jobs:
build:
name: Lint Code Base
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# The job never pushes: don't leave the token in .git/config,
# where anything that archives the workspace picks it up.
persist-credentials: false
# super-linter diffs against DEFAULT_BRANCH to find what changed, which
# needs history. The default depth of 1 leaves it nothing to diff.
fetch-depth: 0
- name: Lint Code Base
uses: docker://ghcr.io/super-linter/super-linter@sha256:c39e6bf032eb532aea6d54b2ae64e44a1df95345337f03e96fce9944f3c9ef9c # v8.2.0
env:
# The built-in token, not a PAT. super-linter is third-party code
# running on every push; all it needs is statuses:write, which the
# permissions block above grants.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
DEFAULT_BRANCH: main
# Changed files only. VALIDATE_ALL_CODEBASE=true reported 159 findings
# across the whole tree on every run, so this job has been red for
# ~90 consecutive runs and nobody could act on it. Scoped to the diff
# it gates new code, which is the part anyone can actually fix.
VALIDATE_ALL_CODEBASE: false
# Helm templates are Go templates that happen to end in .yaml.
# `{{- if .Values.x }}` is not YAML and yamllint cannot parse it, so
# those files failed structurally rather than for anything wrong with
# them. `make helm-template` renders and validates them properly.
# catalog-info.yaml is a Backstage entity: it has an
# apiVersion and a kind, so kubeconform validates it as a
# Kubernetes manifest and fails on a schema that does not
# exist. It is not one, and there is nothing to fix in it.
FILTER_REGEX_EXCLUDE: (kubernetes/helm/templates/.*|catalog-info\.yaml)
# Renamed from DOCKERFILE_HADOLINT_FILE_NAME in v6; resolved relative
# to LINTER_RULES_PATH, which still defaults to .github/linters.
DOCKERFILE_HADOLINT_CONFIG_FILE: .hadolint.yml
# Turned off explicitly, each for its own reason. super-linter's
# rule is that setting VALIDATE_* to false disables exactly those and
# leaves everything else on, so new linters in a future release do
# arrive enabled — the trade for using the mechanism that actually
# works. (ENABLE_LINTERS, the allow-list form, is silently ignored by
# v8: it appears nowhere in the run log and every linter still ran.)
#
# 101 pre-existing findings; wants a .golangci.yml pass of its own
# before it can gate anything.
#
# GO_MODULES is the same golangci-lint reading the same config, so it
# goes with it. It cannot pass as things stand either way:
# .github/linters/.golangci.yml is a v1 config — no `version:` key,
# and it still disables interfacer/maligned/scopelint, removed from
# golangci-lint years ago — while super-linter v8 ships golangci-lint
# 2.5.0, which rejects it with "unsupported version of the
# configuration" before looking at any Go at all.
VALIDATE_GO: false
VALIDATE_GO_MODULES: false
# IaC findings against test/full-setup/kubernetes, which is a local
# test rig rather than a deployment. 73 and 5 findings respectively.
VALIDATE_TRIVY: false
VALIDATE_CHECKOV: false
# Wants one space before a trailing `#`; the SHA-pinning convention
# across these repos uses two, in ~500 places.
VALIDATE_YAML_PRETTIER: false
# Duplication and JS style opinions over legacy code.
VALIDATE_JSCPD: false
VALIDATE_BIOME_FORMAT: false
VALIDATE_BIOME_LINT: false