diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml new file mode 100644 index 0000000..7135ba5 --- /dev/null +++ b/.github/workflows/validate.yml @@ -0,0 +1,47 @@ +name: Validate + +on: + pull_request: + branches: [main] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + templates: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7.0.1 + with: + persist-credentials: false + + # Unraid silently drops a template it can't parse, so fail here instead. + - name: Templates are well-formed and each has its icon + run: | + status=0 + for f in templates/*.xml; do + name=$(basename "$f" .xml) + python3 -c 'import sys, xml.dom.minidom; xml.dom.minidom.parse(sys.argv[1])' "$f" || status=1 + [ -f "icons/$name.png" ] || { echo "missing icons/$name.png"; status=1; } + grep -q "https://raw.githubusercontent.com/drumandbytes/unraid-templates/main/templates/$name.xml" "$f" \ + || { echo "$f: TemplateURL doesn't point at itself"; status=1; } + done + exit $status + + zizmor: + uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 + + # The one name the org ruleset requires. + required-checks-passed: + name: Required checks passed + runs-on: ubuntu-latest + needs: [templates, zizmor] + if: always() + steps: + - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') + run: exit 1 diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..9735430 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + unpinned-uses: + config: + policies: + # GitHub's and our own actions on tags; third-party SHA-pinned. + "actions/*": ref-pin + "drumandbytes/*": ref-pin + "*": hash-pin