From 08b9d4770566f02d0fe8af3e02ddcc1674e9a831 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Bru=C5=BEina?= Date: Sat, 26 Sep 2026 10:25:55 +0200 Subject: [PATCH 1/3] feat: expose megalinter as reusable workflow --- .github/workflows/megalinter.yaml | 31 +++++++++++---------- .markdownlint.yaml | 3 -- .mega-linter.yml | 8 ------ .yamllint.yaml | 7 ----- README.md | 46 ++++++++++++++++++++++++++++--- 5 files changed, 59 insertions(+), 36 deletions(-) delete mode 100644 .markdownlint.yaml delete mode 100644 .yamllint.yaml diff --git a/.github/workflows/megalinter.yaml b/.github/workflows/megalinter.yaml index 84156fd..84cf786 100644 --- a/.github/workflows/megalinter.yaml +++ b/.github/workflows/megalinter.yaml @@ -2,27 +2,25 @@ name: MegaLinter on: pull_request: - paths: - - '**/*.md' - - '**/*.yml' - - '**/*.yaml' - - '.markdownlint.yaml' - - '.mega-linter.yml' - - '.yamllint.yaml' - - '.github/workflows/megalinter.yaml' + workflow_call: + inputs: + validate_all_codebase: + type: boolean + required: false + default: false + description: Lint the whole repository instead of the files changed by the pull request. concurrency: group: megalinter-${{ github.ref }} cancel-in-progress: true -permissions: - contents: write - pull-requests: write - jobs: megalinter: name: MegaLinter runs-on: ubuntu-latest + permissions: + contents: write + pull-requests: write steps: - name: Checkout repository # zizmor: ignore[artipacked] credentials are needed for the auto-commit push; this workflow uploads no artifacts uses: actions/checkout@v7 @@ -30,10 +28,15 @@ jobs: fetch-depth: 0 ref: ${{ github.event.pull_request.head.repo.full_name == github.repository && github.head_ref || '' }} - name: MegaLinter - uses: oxsecurity/megalinter/flavors/documentation@v9 + uses: oxsecurity/megalinter/flavors/terraform@v10 env: APPLY_FIXES: all - VALIDATE_ALL_CODEBASE: false + VALIDATE_ALL_CODEBASE: ${{ inputs.validate_all_codebase || false }} + ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: GITHUB_TOKEN + DISABLE_LINTERS: YAML_PRETTIER + MARKDOWN_FILTER_REGEX_EXCLUDE: "(CHANGELOG\\.md)" + SHOW_ELAPSED_TIME: true + FLAVOR_SUGGESTIONS: false GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Commit applied fixes if: github.event.pull_request.head.repo.full_name == github.repository diff --git a/.markdownlint.yaml b/.markdownlint.yaml deleted file mode 100644 index 95cc969..0000000 --- a/.markdownlint.yaml +++ /dev/null @@ -1,3 +0,0 @@ ---- -default: true -MD013: false # line length diff --git a/.mega-linter.yml b/.mega-linter.yml index 5d5dd98..f3d68f8 100644 --- a/.mega-linter.yml +++ b/.mega-linter.yml @@ -3,11 +3,3 @@ ENABLE: - ACTION - MARKDOWN - YAML -DISABLE_LINTERS: - - YAML_PRETTIER -ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: - - GITHUB_TOKEN -# CHANGELOG.md is generated by semantic-release -MARKDOWN_FILTER_REGEX_EXCLUDE: "(CHANGELOG\\.md)" -SHOW_ELAPSED_TIME: true -FLAVOR_SUGGESTIONS: false diff --git a/.yamllint.yaml b/.yamllint.yaml deleted file mode 100644 index f28a9f8..0000000 --- a/.yamllint.yaml +++ /dev/null @@ -1,7 +0,0 @@ ---- -extends: default - -rules: - line-length: disable - truthy: - check-keys: false diff --git a/README.md b/README.md index 71271d1..5d32393 100644 --- a/README.md +++ b/README.md @@ -5,12 +5,16 @@ Reusable GitHub Actions workflows forming the CI baseline for every BruzIT repos ## Features - [Semantic Release Workflow](#reusable-semantic-release-workflow) -- [Linting](#linting) +- [MegaLinter Workflow](#reusable-megalinter-workflow) ### Reusable Semantic Release Workflow Reusable [Semantic Release workflow](.github/workflows/semantic-release.yaml) using the Conventional Commits preset to automate versioning, tags with SemVer and major tag, generates [GitHub releases](https://github.com/bruzit/github-actions-and-workflows/releases), and updates the [CHANGELOG](CHANGELOG.md). +### Reusable MegaLinter Workflow + +Reusable [MegaLinter workflow](.github/workflows/megalinter.yaml) linting pull requests with the `terraform` flavor, auto-committing fixable findings. Linters run with MegaLinter's default rules, except zizmor, whose [`zizmor.yaml`](zizmor.yaml) allows tag-pinned actions. + ## Usage ### Use Semantic Release Workflow @@ -78,16 +82,50 @@ To create a GitHub App and a GitHub App Installation: Configure Semantic Release in the repository, for example like this repository's [`.releaserc.yaml`](.releaserc.yaml). +### Use MegaLinter Workflow + +Create `.github/workflows/megalinter.yaml`: + +```yaml +--- +name: MegaLinter + +on: + pull_request: + +jobs: + megalinter: + name: MegaLinter + uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0 + permissions: + contents: write + pull-requests: write + # with: + # validate_all_codebase: true # OPTIONAL Lint the whole repository, not only the changed files. +``` + +Create `.mega-linter.yml` listing the linters for the repository, for example: + +```yaml +--- +ENABLE: + - ACTION + - MARKDOWN + - YAML +``` + +Add `ANSIBLE`, `BASH` or `TERRAFORM` to `ENABLE` as needed; ansible-lint additionally requires an `.ansible-lint` file. Copy [`zizmor.yaml`](zizmor.yaml) into the repository root and add `megalinter-reports/` to `.gitignore`. + ## Linting -Markdown is linted with [MegaLinter](https://megalinter.io). Run locally (needs Docker): +This repository is linted by its own [MegaLinter workflow](.github/workflows/megalinter.yaml). Run locally (needs Docker): ```bash # report issues -docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-documentation:v9 +docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10 # auto-fix where possible -docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-documentation:v9 +docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10 ``` ## Copyright and Licensing From ab7c163cac8bf4946fbca6e42c0c006b22766390 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Bru=C5=BEina?= Date: Sat, 26 Sep 2026 10:25:55 +0200 Subject: [PATCH 2/3] ci: ignore zizmor adhoc-packages on the semantic release install --- .github/workflows/semantic-release.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/semantic-release.yaml b/.github/workflows/semantic-release.yaml index f3d1e60..c1f406e 100644 --- a/.github/workflows/semantic-release.yaml +++ b/.github/workflows/semantic-release.yaml @@ -52,7 +52,7 @@ jobs: uses: actions/setup-node@v7 with: node-version: 'lts/*' - - name: Install Semantic Release + - name: Install Semantic Release # zizmor: ignore[adhoc-packages] lockfiles are not committed by design env: SEMANTIC_RELEASE_PLUGINS: ${{ inputs.semantic_release_plugins }} run: | From fe8a11660e047ddbafa345664b7f533f60424afd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Bru=C5=BEina?= Date: Sat, 26 Sep 2026 10:35:23 +0200 Subject: [PATCH 3/3] docs: add scheduled full-scan megalinter caller example --- README.md | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/README.md b/README.md index 5d32393..ceb9982 100644 --- a/README.md +++ b/README.md @@ -116,6 +116,30 @@ ENABLE: Add `ANSIBLE`, `BASH` or `TERRAFORM` to `ENABLE` as needed; ansible-lint additionally requires an `.ansible-lint` file. Copy [`zizmor.yaml`](zizmor.yaml) into the repository root and add `megalinter-reports/` to `.gitignore`. +Pull requests lint only changed files. To also lint the whole repository weekly, for example to catch newly published advisories for pinned action tags, create `.github/workflows/megalinter-scheduled.yaml`: + +```yaml +--- +name: MegaLinter Scheduled + +on: + schedule: + - cron: "0 6 * * 1" + workflow_dispatch: + +jobs: + megalinter: + name: MegaLinter + uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0 + permissions: + contents: write + pull-requests: write + with: + validate_all_codebase: true +``` + +Fixes are not committed outside pull requests; findings fail the run. + ## Linting This repository is linted by its own [MegaLinter workflow](.github/workflows/megalinter.yaml). Run locally (needs Docker):