Skip to content

Repository files navigation

GitHub Actions and Workflows

Reusable GitHub Actions and workflows forming the CI baseline for every BruzIT repository: semantic-release versioning and MegaLinter linting.

Features

Semantic Release Composite Action

Semantic Release composite action using the Conventional Commits preset to automate versioning, tags with SemVer and major tag, generates GitHub releases, and updates the CHANGELOG. It checks out the repository with the GitHub App token, so the changelog commit and the major tags are pushed as the GitHub App; without app-id it uses GITHUB_TOKEN.

Reusable MegaLinter Workflow

Reusable MegaLinter workflow linting pull requests with the terraform flavor, auto-committing fixable findings. Linters run with MegaLinter's default rules, except zizmor, whose zizmor.yaml allows tag-pinned actions.

Usage

Use Semantic Release Action

Create a workflow, for example, .github/workflows/semantic-release.yaml:

---
name: Semantic Release

on:
  push:
    branches:
      - main

jobs:
  release:
    name: Release
    runs-on: ubuntu-latest
    permissions:
      contents: write
      issues: write
      pull-requests: write
    steps:
      - name: Semantic Release
        uses: bruzit/github-actions-and-workflows/semantic-release@v0
        with:
          app-id: ${{ vars.GH_SEM_REL_APP_ID }}
          app-private-key: ${{ secrets.GH_SEM_REL_APP_PEM_FILE }}
          plugins: "@semantic-release/exec" # OPTIONAL Space-separated list of additional semantic-release plugins to install.

The action checks out the repository itself. A local uses: ./semantic-release needs a prior actions/checkout with persist-credentials: false.

To create a GitHub App and a GitHub App Installation:

  • GitHub
    • Organization / Settings / Developer settings / GitHub Apps
      • New GitHub App
        • Create GitHub App
          • GitHub App name: name
          • Description: description
          • Homepage URL: homepage URL
        • Webhook
          • Active: off
        • Permissions
          • Organization permissions
            • Contents: Read and write
            • Issues: Read and write
            • Pull requests: Read and write
          • Where can this GitHub App be installed?: choose what suits you best
        • Create GitHub App
      • your app
        • General
          • Generate a private key
        • Install App
          • your organization: Install
    • Repository / Settings / Secrets and variables / Actions
      • Secrets
        • Repository secrets / New repository secret
          • Name: GH_SEM_REL_APP_PEM_FILE
          • Secret: content of the PEM file
          • Add secret
      • Variables
        • Repository variables / New repository variable
          • Name: GH_SEM_REL_APP_ID
          • Value: GitHub App ID
          • Add variable

Configure Semantic Release in the repository, for example like this repository's .releaserc.yaml.

Use MegaLinter Workflow

Create .github/workflows/megalinter.yaml:

---
name: MegaLinter

on:
  pull_request:

jobs:
  megalinter:
    name: MegaLinter
    uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
    permissions:
      contents: write
      pull-requests: write
    # with:
    #   validate_all_codebase: true # OPTIONAL Lint the whole repository, not only the changed files.

Create .mega-linter.yml listing the linters for the repository, for example:

---
ENABLE:
  - ACTION
  - MARKDOWN
  - YAML

Add ANSIBLE, BASH or TERRAFORM to ENABLE as needed; ansible-lint additionally requires an .ansible-lint file. Copy zizmor.yaml into the repository root and add megalinter-reports/ to .gitignore.

Pull requests lint only changed files. To also lint the whole repository weekly, for example to catch newly published advisories for pinned action tags, create .github/workflows/megalinter-scheduled.yaml:

---
name: MegaLinter Scheduled

on:
  schedule:
    - cron: "0 6 * * 1"
  workflow_dispatch:

jobs:
  megalinter:
    name: MegaLinter
    uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
    permissions:
      contents: write
      pull-requests: write
    with:
      validate_all_codebase: true

Fixes are not committed outside pull requests; findings fail the run.

Linting

This repository is linted by its own MegaLinter workflow. Run locally (needs Docker):

# report issues
docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10

# auto-fix where possible
docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10

Copyright and Licensing

MIT License
Copyright © 2026 Martin Bružina

About

Reusable GitHub Actions workflows forming the CI baseline for every BruzIT repository: semantic-release versioning and MegaLinter linting.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors