Ignore actionlint's false positive for job.workflow_sha and job.workflow_repository. Closes #139 - #140
Conversation
…low_repository. Closes #139 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e docker action does not honour. Closes #139 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
plamber
left a comment
There was a problem hiding this comment.
No blockers. One WHITE: the ignore is a little wider than its comment says.
| Finding | Where | |
|---|---|---|
| ⚪ | Pattern is unanchored and \S* accepts trailing characters, so job.workflow_shax would also be ignored; comment says "exactly" |
.github/workflows/workflow_lint.yml:57 |
Good: the final args form was run as the real docker step on a throwaway branch (the quoted first attempt failed there), and a genuinely undefined property is still reported.
Generated by Claude Code
| # contain neither: \s stands in for each space. | ||
| args: >- | ||
| -color | ||
| -ignore workflow_(sha|repository)\S*\sis\snot\sdefined\sin\sobject\stype\s\{check_run_id |
There was a problem hiding this comment.
⚪ Unanchored, and \S* accepts any trailing characters, so a typo like job.workflow_shax or job.my_workflow_repository is ignored too, which the comment's "exactly those two messages" denies. The {check_run_id tail limits it to the job context, so the blast radius is small. Anchor the property name with \x22 (RE2 escape, no quote character in the argument): property\s\x22workflow_(sha|repository)\x22\sis\snot\sdefined\sin\sobject\stype\s\{check_run_id, and say in the comment that the tail scopes it to the job context.
… scopes it. Closes #139 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Closes #139.
actionlint 1.7.12 (the latest release) predates
job.workflow_sha/job.workflow_repository, whichpr_compliance.ymlandpr_agent_review.ymluse on purpose, socall-workflow-lint / actionlintfails on every pull request. This passes-ignorefor exactly those two properties on the job context.Verified
job.nonexistent_thing,job.workflow_shax,job.my_workflow_repository.docker://rhysd/actionlintstep with thisargsblock, on a throwaway branch in real Actions: passes (branch deleted). A first attempt with a quoted pattern failed there: the action splitsargson whitespace and ignores quotes, which is why the pattern uses\sand\x22and the comment says so.This pull request's own
call-workflow-lint / actionlintstays red until it merges, becausepr-review.ymlcalls the reusable workflow at@main, which is still the old file. That is the expected state, and the throwaway-branch run above is the proof.Changed after review
{check_run_idtail is what scopes the ignore to the job context.🤖 Generated with Claude Code