Skip to content

Ignore actionlint's false positive for job.workflow_sha and job.workflow_repository. Closes #139 - #140

Merged
plamber merged 3 commits into
mainfrom
fix/actionlint-job-workflow-sha
Sep 30, 2026
Merged

plamber merged 3 commits into
mainfrom
fix/actionlint-job-workflow-sha

Conversation

@easylife-agents

@easylife-agents easylife-agents Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Closes #139.

actionlint 1.7.12 (the latest release) predates job.workflow_sha / job.workflow_repository, which pr_compliance.yml and pr_agent_review.yml use on purpose, so call-workflow-lint / actionlint fails on every pull request. This passes -ignore for exactly those two properties on the job context.

Verified

  • Real actionlint 1.7.12 binary, locally, on the current tree (4 errors before): 0 errors with the ignore.
  • Still reported with the ignore: job.nonexistent_thing, job.workflow_shax, job.my_workflow_repository.
  • The exact docker://rhysd/actionlint step with this args block, on a throwaway branch in real Actions: passes (branch deleted). A first attempt with a quoted pattern failed there: the action splits args on whitespace and ignores quotes, which is why the pattern uses \s and \x22 and the comment says so.

This pull request's own call-workflow-lint / actionlint stays red until it merges, because pr-review.yml calls the reusable workflow at @main, which is still the old file. That is the expected state, and the throwaway-branch run above is the proof.

Changed after review

  • 08b0944 answers the one WHITE finding: the pattern is anchored on the quoted property name, and the comment now says the {check_run_id tail is what scopes the ignore to the job context.
  • 866aeb4 precedes the review: it is the quoting fix found by the real run, not new scope.

🤖 Generated with Claude Code

…low_repository. Closes #139

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@easylife-agents
easylife-agents Bot marked this pull request as ready for review September 30, 2026 17:37
…e docker action does not honour. Closes #139

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@plamber plamber left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blockers. One WHITE: the ignore is a little wider than its comment says.

Finding Where
⚪ Pattern is unanchored and \S* accepts trailing characters, so job.workflow_shax would also be ignored; comment says "exactly" .github/workflows/workflow_lint.yml:57

Good: the final args form was run as the real docker step on a throwaway branch (the quoted first attempt failed there), and a genuinely undefined property is still reported.


Generated by Claude Code

Comment thread .github/workflows/workflow_lint.yml Outdated
# contain neither: \s stands in for each space.
args: >-
-color
-ignore workflow_(sha|repository)\S*\sis\snot\sdefined\sin\sobject\stype\s\{check_run_id

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚪ Unanchored, and \S* accepts any trailing characters, so a typo like job.workflow_shax or job.my_workflow_repository is ignored too, which the comment's "exactly those two messages" denies. The {check_run_id tail limits it to the job context, so the blast radius is small. Anchor the property name with \x22 (RE2 escape, no quote character in the argument): property\s\x22workflow_(sha|repository)\x22\sis\snot\sdefined\sin\sobject\stype\s\{check_run_id, and say in the comment that the tail scopes it to the job context.

… scopes it. Closes #139

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@easylife-agents
easylife-agents Bot requested a review from plamber September 30, 2026 17:44
@plamber
plamber merged commit ba36604 into main Sep 30, 2026
10 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Workflow lint reports job.workflow_sha as undefined on every pull request

1 participant