From c315c8f7a8b301fa4d1cd5898df9a5f79397b141 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C4=81ris=20Pop=C4=93ns?= Date: Mon, 28 Sep 2026 07:38:21 +0300 Subject: [PATCH 1/2] ci: validate templates and satisfy the org's required check --- .github/workflows/validate.yml | 48 ++++++++++++++++++++++++++++++++++ .github/zizmor.yml | 8 ++++++ 2 files changed, 56 insertions(+) create mode 100644 .github/workflows/validate.yml create mode 100644 .github/zizmor.yml diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml new file mode 100644 index 0000000..52a3418 --- /dev/null +++ b/.github/workflows/validate.yml @@ -0,0 +1,48 @@ +name: Validate + +on: + pull_request: + branches: [main] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + templates: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7.0.1 + with: + persist-credentials: false + + # Unraid silently drops a template it can't parse, so fail here instead. + - name: Templates are well-formed and each has its icon + run: | + sudo apt-get install -y -qq libxml2-utils >/dev/null + status=0 + for f in templates/*.xml; do + name=$(basename "$f" .xml) + xmllint --noout "$f" || status=1 + [ -f "icons/$name.png" ] || { echo "missing icons/$name.png"; status=1; } + grep -q "https://raw.githubusercontent.com/drumandbytes/unraid-templates/main/templates/$name.xml" "$f" \ + || { echo "$f: TemplateURL doesn't point at itself"; status=1; } + done + exit $status + + zizmor: + uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 + + # The one name the org ruleset requires. + required-checks-passed: + name: Required checks passed + runs-on: ubuntu-latest + needs: [templates, zizmor] + if: always() + steps: + - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') + run: exit 1 diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..9735430 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + unpinned-uses: + config: + policies: + # GitHub's and our own actions on tags; third-party SHA-pinned. + "actions/*": ref-pin + "drumandbytes/*": ref-pin + "*": hash-pin From d4a82eb35a0fdc33c73b7df963ce050b97e53515 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C4=81ris=20Pop=C4=93ns?= Date: Mon, 28 Sep 2026 07:41:02 +0300 Subject: [PATCH 2/2] ci: parse templates with Python instead of apt-installing xmllint --- .github/workflows/validate.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 52a3418..7135ba5 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -23,11 +23,10 @@ jobs: # Unraid silently drops a template it can't parse, so fail here instead. - name: Templates are well-formed and each has its icon run: | - sudo apt-get install -y -qq libxml2-utils >/dev/null status=0 for f in templates/*.xml; do name=$(basename "$f" .xml) - xmllint --noout "$f" || status=1 + python3 -c 'import sys, xml.dom.minidom; xml.dom.minidom.parse(sys.argv[1])' "$f" || status=1 [ -f "icons/$name.png" ] || { echo "missing icons/$name.png"; status=1; } grep -q "https://raw.githubusercontent.com/drumandbytes/unraid-templates/main/templates/$name.xml" "$f" \ || { echo "$f: TemplateURL doesn't point at itself"; status=1; }