Skip to content

CI: fail on undefined variables, lint workflows, update actions - #376

Open
jackspiering wants to merge 2 commits into
mainfrom
ci-strict-validation
Open

jackspiering wants to merge 2 commits into
mainfrom
ci-strict-validation

Conversation

@jackspiering

@jackspiering jackspiering commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Tightens the Compose validation and lint workflows.

  • Compose validation:
    • "variable is not set" warnings are now errors.
    • The template is validated too.
    • A required variable that .env does not list is flagged.
    • The Tailscale Serve JSON must parse.
    • The paths: filters are removed, so the check runs on every pull request and can be made required.
    • The job is named Compose files, and the log shows the Compose version.
  • Formbricks: the 41 variables that existed only as comments in .env are now empty values (this is what produced the warnings). The rendered Compose output is identical before and after.
  • Linting: removes the paths-ignore blocks, so a PR that touches only LICENSE or .gitignore cannot stay "Pending". Adds a step that fails when the rumdl action version and its version: input disagree.
  • persist-credentials: false on every checkout.
  • New workflow-lint.yml (actionlint and zizmor, only on .github/** changes, with the same concurrency block as the other workflows), and dependabot.yml for the pinned actions.

Related Issues

  • None.

Verification

  • The new step, run locally with bash -eo pipefail against Compose v5.6.0 and v2.38.2 (the runner's version): exit 0 on this branch. Before the Formbricks fix it flags only Formbricks, with the 41 names. A broken Serve JSON and a renamed required variable are both flagged. EspoCRM needs at most 4 dummy variables.
  • actionlint 1.7.12 and zizmor 1.30.1 report nothing on all workflows.
  • Pins checked against upstream: actions/checkout v7.0.1, zizmor-action v0.6.4, and the actionlint sha256.
  • All three workflows ran on this pull request and passed.

Checklist

  • I have performed a self-review of my code and followed the templates structure.
  • I have added verification that the stack works as expected.
  • I have updated necessary documentation (e.g. frontpage README.md ).
  • I have selected the correct label(s) for this PR.

Additional Context

From an external review of the repository (section 4).

  • After merging, an admin can add Compose files to the required status checks of main. lint keeps its name, because branch protection requires it.
  • Workflow lint should not be required.
  • Not included: the repository conventions job and the weekly link check.

The other two workflows cancel a superseded pull request run. The workflow lint now does the same.
@jackspiering
jackspiering requested a review from crypt0rr October 10, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant