Repository navigation
ci: add Validate Code workflow required by org ruleset #15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,95 @@ | ||
| name: Validate | ||
|
|
||
| on: | ||
| pull_request: | ||
| types: [opened, edited, synchronize, reopened] | ||
| branches: | ||
| - main | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| validate: | ||
| name: Validate Action | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - name: Validate action metadata | ||
| run: | | ||
| python3 - <<'PY' | ||
| import sys, yaml | ||
|
|
||
| action = yaml.safe_load(open("action.yml")) | ||
|
Comment on lines
+29
to
+31
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/pull-request.yml
printf '%s\n' '--- repository conventions ---'
find /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f -type f -name '*.md' -maxdepth 4 -print \
| sort
printf '%s\n' '--- scoped convention and learning content ---'
for f in /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f/{conventions,learnings,architecture}/*.md; do
[ -f "$f" ] || continue
printf '\n### %s\n' "$f"
cat "$f"
done
printf '%s\n' '--- dependency declarations and yaml usage ---'
rg -n --hidden -S 'import yaml|PyYAML|pip install|yaml\.safe_load|yaml\.safe_dump' \
.github action.yml requirements\*.txt pyproject.toml setup.cfg setup.py 2>/dev/null || trueRepository: archgate/setup-action Length of output: 5287 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/pull-request.yml
printf '%s\n' '--- repository conventions and learnings ---'
find /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f \
-type f -name '*.md' -maxdepth 4 -print -exec sh -c '
printf "\n### %s\n" "$1"
cat "$1"
' sh {} \;
printf '%s\n' '--- dependency declarations and yaml usage ---'
rg -n --hidden -S 'import yaml|PyYAML|pip install|yaml\.safe_load|yaml\.safe_dump' \
.github action.yml requirements\*.txt pyproject.toml setup.cfg setup.py 2>/dev/null || trueRepository: archgate/setup-action Length of output: 5254 🌐 Web query:
💡 Result: As of September 1, 2026, the GitHub Actions Citations:
Provision PyYAML before running the validators. Both inline Python validators import 🤖 Prompt for AI Agents |
||
|
|
||
| errors = [] | ||
| for key in ("name", "description", "runs"): | ||
| if not action.get(key): | ||
| errors.append(f"action.yml is missing required key: {key}") | ||
|
|
||
| runs = action.get("runs") or {} | ||
| if runs.get("using") != "composite": | ||
| errors.append(f"action.yml runs.using must be 'composite', got {runs.get('using')!r}") | ||
|
|
||
| for i, step in enumerate(runs.get("steps") or []): | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- applicable repository conventions ---'
find /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f -type f -name '*.md' -print
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/pull-request.yml | sed -n '1,130p'
printf '%s\n' '--- action metadata ---'
cat -n action.yml | sed -n '1,180p'
printf '%s\n' '--- repository workflow/action files ---'
git ls-files '.github/workflows/*' 'action.yml' '*.yaml' '*.yml' | sed -n '1,160p'Repository: archgate/setup-action Length of output: 5943 🏁 Script executed: #!/bin/bash
set -eu
cat /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f/conventions/repo-wide.mdRepository: archgate/setup-action Length of output: 1060 🌐 Web query:
💡 Result: In a GitHub composite action, the steps defined under the runs.steps configuration are required for the action to execute tasks [1][2]. While the overall steps list itself is not inherently "empty" in a functional action, if you define a composite action with an empty steps list, it will effectively perform no operations when invoked. Regarding metadata syntax requirements for composite actions: 1. Runs Steps: The steps key within the runs section is required to define the execution flow [1][2]. Each step within this list can be a run step or a uses step [1][2]. 2. Shell Requirement: For any run step defined within a composite action, the shell attribute is strictly required [3][4]. Unlike standard workflow jobs, composite run steps do not inherit a default shell; you must explicitly define one (e.g., bash, pwsh, python, sh, cmd, or powershell) for every run step [3][4]. 3. Description: Although often listed as required in general metadata documentation, the description key is not strictly enforced at runtime for composite actions [5][6]. The action will still function if the key is omitted, though it remains highly recommended for documentation purposes [5][6]. If you provide an empty list for steps (e.g., steps: []), the action will complete successfully without performing any work [5][6]. Citations:
🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- ADR and rule files ---'
git ls-files '.archgate/adrs/*' | sed -n '1,120p'
printf '%s\n' '--- references to composite metadata or steps ---'
rg -n -i 'composite|runs\.steps|action\.yml|metadata|non-empty|nonempty' .archgate/adrs .github action.yml --glob '*.md' --glob '*.ts' --glob '*.yml' --glob '*.yaml' || trueRepository: archgate/setup-action Length of output: 1225 Reject composite metadata without
🤖 Prompt for AI Agents |
||
| if "run" in step and not step.get("shell"): | ||
| errors.append(f"action.yml step {i} ({step.get('name', 'unnamed')}) has 'run' without 'shell'") | ||
|
|
||
| for e in errors: | ||
| print(f"::error file=action.yml::{e}") | ||
| sys.exit(1 if errors else 0) | ||
| PY | ||
|
|
||
| - name: Verify all actions are pinned to a full commit SHA | ||
| run: | | ||
| python3 - <<'PY' | ||
| import pathlib, re, sys, yaml | ||
|
|
||
| SHA = re.compile(r"^[0-9a-f]{40}$") | ||
| failures = [] | ||
|
|
||
| def check(path, node): | ||
| if isinstance(node, dict): | ||
| uses = node.get("uses") | ||
| if isinstance(uses, str) and not uses.startswith(("./", "docker://")): | ||
| ref = uses.partition("@")[2] | ||
| if not SHA.match(ref): | ||
|
Comment on lines
+62
to
+64
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: # Inspect the validator and the repository's workflow review conventions only.
printf '%s\n' '--- pull-request workflow ---'
sed -n '1,130p' .github/workflows/pull-request.yml
printf '%s\n' '--- scoped conventions ---'
find /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f -type f -path '*/conventions/*' -o -path '*/rules/*' | sortRepository: archgate/setup-action Length of output: 3354 🏁 Script executed: # Read the repository-wide convention file that governs this workflow review.
cat /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f/conventions/repo-wide.mdRepository: archgate/setup-action Length of output: 1060 🏁 Script executed: # Check the authoritative ADRs for the action-pinning policy and Docker-reference scope.
fd -t f . .archgate/adrs .archgate 2>/dev/null | sort
rg -n -i -C 3 'pin|sha|docker|workflow|action' .archgate/adrs 2>/dev/nullRepository: archgate/setup-action Length of output: 159 Security Misconfiguration (CWE-494): Download of Code Without Integrity Check Reachability: External · Exploitability: Moderate Validate Docker action references instead of skipping them. The 🤖 Prompt for AI Agents |
||
| failures.append(f"{path}: '{uses}' is not pinned to a full commit SHA") | ||
| for value in node.values(): | ||
| check(path, value) | ||
| elif isinstance(node, list): | ||
| for value in node: | ||
| check(path, value) | ||
|
|
||
| paths = [pathlib.Path("action.yml"), *sorted(pathlib.Path(".github/workflows").glob("*.yml"))] | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- repository conventions and learnings ---'
find /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f -type f -name '*.md' -maxdepth 3 -print
printf '%s\n' '--- workflow files ---'
find .github/workflows -maxdepth 1 -type f \( -name '*.yml' -o -name '*.yaml' \) -print | sort
printf '%s\n' '--- changed validation code ---'
sed -n '55,90p' .github/workflows/pull-request.yml
printf '%s\n' '--- uses references in YAML workflows ---'
rg -n '^[[:space:]]*uses:' .github/workflows -g '*.yml' -g '*.yaml' || true
printf '%s\n' '--- applicable convention and learning content ---'
for f in /tmp/coderabbit-repo-knowledge/archgate-setup-action-ffa0529f/{conventions,learnings,architecture}/*.md; do
[ -f "$f" ] && { echo "### $f"; cat "$f"; }
doneRepository: archgate/setup-action Length of output: 3047 Security Misconfiguration (CWE-693) Reachability: External · Exploitability: Moderate Include
🤖 Prompt for AI Agents |
||
| for path in paths: | ||
| check(path, yaml.safe_load(path.read_text())) | ||
|
|
||
| for f in failures: | ||
| print(f"::error::{f}") | ||
| print(f"Checked {len(paths)} file(s).") | ||
| sys.exit(1 if failures else 0) | ||
| PY | ||
|
|
||
| # Gate job — single required status check for the org ruleset. | ||
| status: | ||
| name: Validate Code | ||
| runs-on: ubuntu-latest | ||
| if: always() | ||
| needs: [validate] | ||
| steps: | ||
| - name: Check job results | ||
| run: | | ||
| if [[ "${{ needs.validate.result }}" != "success" ]]; then | ||
| echo "::error::Validation failed: ${{ needs.validate.result }}" | ||
| exit 1 | ||
| fi | ||
| echo "All checks passed." | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: archgate/setup-action
Length of output: 4816
Authorization Bypass (CWE-693)
Reachability: External · Exploitability: Moderate
Run
Validate Codefrom a trusted workflow revision.pull_requestevaluates this workflow from the pull request merge ref. A pull request can modify the validators or theValidate Codegate and still pass the required check. Use a trusted base-branch workflow, such aspull_request_targetwith read-only permissions, and inspect the pull request revision without executing its scripts.🤖 Prompt for AI Agents