Skip to content

build(ci): bump github/super-linter to v7 and fix yaml-lint config - #9184

Open
DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:ci/super-linter-v7
Open

DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:ci/super-linter-v7

Conversation

@DoDiODev

Copy link
Copy Markdown
Contributor

Summary

Supersedes #9104 (Dependabot: bump github/super-linter from 4 to 7) and makes the yaml-lint workflow pass with v7.

Why #9104 fails
super-linter v7 aborts when commit status reports are enabled (MULTI_STATUS, default true) and no GITHUB_TOKEN is provided:

[FATAL] Failed to get [GITHUB_TOKEN]. Terminating because status reports were explicitly enabled, but GITHUB_TOKEN was not provided.

v4 only logged this as an error and continued.

Pre-existing issue found along the way
FILTER_REGEX_INCLUDE: workspace/(docker-compose.yml|deployment/k8s/k8s-deploy.yaml) matches no file anymore: there is no root docker-compose.yml, and the k8s manifest lives in devops/deployment/k8s/. The current v4 job on main therefore lints nothing ("The script has completed" without any linter run).

Changes to .github/workflows/yaml-lint.yml

  • github/super-linter/slim@v4 → @v7
  • MULTI_STATUS: false: no token or statuses: write permission needed, and it also works for PRs from forks
  • VALIDATE_YAML: true: only yamllint runs. Otherwise v7 would also run kubeconform, checkov, etc. on the k8s manifest.
  • Fixed FILTER_REGEX_INCLUDE, which now matches devops/deployment/k8s/k8s-deploy.yaml, docker-compose-dev-mysql.yml, docker-compose-dev-postgresql.yml and docker-compose.datasources.yml (works for both relative and absolute paths)
  • fetch-depth: 0 on checkout, as recommended by super-linter

Verified locally with yamllint 1.x and the super-linter v7 default .yaml-lint.yml: warnings only (document-start, line-length), no errors.

Does this close any open issues?

Supersedes #9104

Other Information

github/super-linter is a GitHub-maintained fork; upstream super-linter/super-linter is at v8, but would need to be added to the ASF actions allowlist first. Staying on the github/* namespace avoids that.

- disable MULTI_STATUS so no GITHUB_TOKEN is required (v7 aborts otherwise)
- restrict to yamllint via VALIDATE_YAML
- fix FILTER_REGEX_INCLUDE, which matched no files since the repo layout changed
- fetch full history as recommended by super-linter

Signed-off-by: DoDiODev <DoDiDev@proton.me>
@DoDiODev

Copy link
Copy Markdown
Contributor Author

Verification run from my fork (throwaway PR DoDiODev#59, same commit, base = upstream/main b0a7589): https://github.com/DoDiODev/devlake/actions/runs/36562234835

  • lint for yamls is green with github/super-linter/slim@v7 (image 7.1.0)
  • GITHUB_TOKEN had read-only permissions (like fork PRs here); no token error thanks to MULTI_STATUS: false
  • yamllint now actually checks the three root docker-compose*.yml files and devops/deployment/k8s/k8s-deploy.yaml: only warnings (document-start, line-length), 0 errors

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant