Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 17 additions & 14 deletions .github/workflows/megalinter.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,38 +2,41 @@
name: MegaLinter
on:
pull_request:
paths:
- '**/*.md'
- '**/*.yml'
- '**/*.yaml'
- '.markdownlint.yaml'
- '.mega-linter.yml'
- '.yamllint.yaml'
- '.github/workflows/megalinter.yaml'
workflow_call:
inputs:
validate_all_codebase:
type: boolean
required: false
default: false
description: Lint the whole repository instead of the files changed by the pull request.

concurrency:
group: megalinter-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: write
pull-requests: write

jobs:
megalinter:
name: MegaLinter
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- name: Checkout repository # zizmor: ignore[artipacked] credentials are needed for the auto-commit push; this workflow uploads no artifacts
uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event.pull_request.head.repo.full_name == github.repository && github.head_ref || '' }}
- name: MegaLinter
uses: oxsecurity/megalinter/flavors/documentation@v9
uses: oxsecurity/megalinter/flavors/terraform@v10
env:
APPLY_FIXES: all
VALIDATE_ALL_CODEBASE: false
VALIDATE_ALL_CODEBASE: ${{ inputs.validate_all_codebase || false }}
ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: GITHUB_TOKEN
DISABLE_LINTERS: YAML_PRETTIER
MARKDOWN_FILTER_REGEX_EXCLUDE: "(CHANGELOG\\.md)"
SHOW_ELAPSED_TIME: true
FLAVOR_SUGGESTIONS: false
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Commit applied fixes
if: github.event.pull_request.head.repo.full_name == github.repository
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/semantic-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ jobs:
uses: actions/setup-node@v7
with:
node-version: 'lts/*'
- name: Install Semantic Release
- name: Install Semantic Release # zizmor: ignore[adhoc-packages] lockfiles are not committed by design
env:
SEMANTIC_RELEASE_PLUGINS: ${{ inputs.semantic_release_plugins }}
run: |
Expand Down
3 changes: 0 additions & 3 deletions .markdownlint.yaml

This file was deleted.

8 changes: 0 additions & 8 deletions .mega-linter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,3 @@ ENABLE:
- ACTION
- MARKDOWN
- YAML
DISABLE_LINTERS:
- YAML_PRETTIER
ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
- GITHUB_TOKEN
# CHANGELOG.md is generated by semantic-release
MARKDOWN_FILTER_REGEX_EXCLUDE: "(CHANGELOG\\.md)"
SHOW_ELAPSED_TIME: true
FLAVOR_SUGGESTIONS: false
7 changes: 0 additions & 7 deletions .yamllint.yaml

This file was deleted.

70 changes: 66 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,16 @@ Reusable GitHub Actions workflows forming the CI baseline for every BruzIT repos
## Features

- [Semantic Release Workflow](#reusable-semantic-release-workflow)
- [Linting](#linting)
- [MegaLinter Workflow](#reusable-megalinter-workflow)

### Reusable Semantic Release Workflow

Reusable [Semantic Release workflow](.github/workflows/semantic-release.yaml) using the Conventional Commits preset to automate versioning, tags with SemVer and major tag, generates [GitHub releases](https://github.com/bruzit/github-actions-and-workflows/releases), and updates the [CHANGELOG](CHANGELOG.md).

### Reusable MegaLinter Workflow

Reusable [MegaLinter workflow](.github/workflows/megalinter.yaml) linting pull requests with the `terraform` flavor, auto-committing fixable findings. Linters run with MegaLinter's default rules, except zizmor, whose [`zizmor.yaml`](zizmor.yaml) allows tag-pinned actions.

## Usage

### Use Semantic Release Workflow
Expand Down Expand Up @@ -78,16 +82,74 @@ To create a GitHub App and a GitHub App Installation:

Configure Semantic Release in the repository, for example like this repository's [`.releaserc.yaml`](.releaserc.yaml).

### Use MegaLinter Workflow

Create `.github/workflows/megalinter.yaml`:

```yaml
---
name: MegaLinter

on:
pull_request:

jobs:
megalinter:
name: MegaLinter
uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
permissions:
contents: write
pull-requests: write
# with:
# validate_all_codebase: true # OPTIONAL Lint the whole repository, not only the changed files.
```

Create `.mega-linter.yml` listing the linters for the repository, for example:

```yaml
---
ENABLE:
- ACTION
- MARKDOWN
- YAML
```

Add `ANSIBLE`, `BASH` or `TERRAFORM` to `ENABLE` as needed; ansible-lint additionally requires an `.ansible-lint` file. Copy [`zizmor.yaml`](zizmor.yaml) into the repository root and add `megalinter-reports/` to `.gitignore`.

Pull requests lint only changed files. To also lint the whole repository weekly, for example to catch newly published advisories for pinned action tags, create `.github/workflows/megalinter-scheduled.yaml`:

```yaml
---
name: MegaLinter Scheduled

on:
schedule:
- cron: "0 6 * * 1"
workflow_dispatch:

jobs:
megalinter:
name: MegaLinter
uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
permissions:
contents: write
pull-requests: write
with:
validate_all_codebase: true
```

Fixes are not committed outside pull requests; findings fail the run.

## Linting

Markdown is linted with [MegaLinter](https://megalinter.io). Run locally (needs Docker):
This repository is linted by its own [MegaLinter workflow](.github/workflows/megalinter.yaml). Run locally (needs Docker):

```bash
# report issues
docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-documentation:v9
docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10

# auto-fix where possible
docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-documentation:v9
docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10
```

## Copyright and Licensing
Expand Down
Loading