Files
gstack/.github/workflows/actionlint.yml
T
Garry TanandClaude Fable 5 e2904be7a4 fix(ci): least-privilege permissions + fork-safe concurrency keys
- evals.yml / evals-periodic.yml evals jobs: explicit contents:read +
  packages:read (container-image pull) and persist-credentials:false —
  the jobs that execute PR-authored code with three provider API keys
  ran on the repo-default token grant with the token written into
  .git/config
- permissions blocks for the 4 workflows that had none (skill-docs,
  make-pdf-gate, windows-free-tests, windows-setup-e2e)
- fork-safe concurrency keys: actionlint, skill-docs, make-pdf-gate,
  windows-setup-e2e switch from head_ref to PR-number keying — a bare
  branch name carries no fork prefix, so same-name branches from two
  forks shared one group and cancelled each other's runs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-29 04:39:36 +00:00

33 lines
1.3 KiB
YAML

name: Workflow Lint
# push is main-only: a push to a PR branch already fires the pull_request run;
# the unrestricted push trigger double-ran every PR commit.
on:
push:
branches: [main]
pull_request:
# PR-number keyed (run_id fallback for push): a bare branch name carries no
# fork prefix, so same-name branches from two forks would share one group and
# cancel each other's runs (same rationale as free-tests.yml).
concurrency:
group: actionlint-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true
# Lint needs nothing from the token; the job runs a third-party image with
# the checkout mounted, so keep the grant read-only and out of .git/config.
permissions:
contents: read
jobs:
actionlint:
runs-on: ubicloud-standard-2
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
# Pull the prebuilt image instead of rhysd/actionlint@v1.7.11 (a Docker
# action that rebuilt from source every run: 16s of a 44s job for 1s of
# lint). Pinned by DIGEST: a Docker Hub tag is repointable with no
# GitHub-side audit trail, and this image sees the mounted checkout.
- run: docker run --rm -v "$PWD:/repo" -w /repo rhysd/actionlint:1.7.11@sha256:6f03470d0152251d7f07f7c4dc019dbe7024c72cd952f839544c7798843efa8f -color