diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index ee038c41..57577b3b 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -56,6 +56,26 @@ jobs: - name: lint run: sh scripts/check-attribution-trailers.sh + shellcheck: + name: shellcheck + runs-on: [hive-ci] + # shellcheck itself is fast; nix shell's first pull of the closure is + # the slow part on a cold cache. + timeout-minutes: 10 + steps: + - uses: actions/checkout@v3 + - name: lint + # Discovers raw shell files by shebang rather than by extension — + # scripts/pre-push ships with no `.sh` suffix, so a `*.sh` glob + # would silently skip it (and any future extensionless script). + # -S warning drops info-level notes: the repo's one SC2016 hit is + # an intentionally single-quoted awk program, not a bug, and this + # keeps the gate free of a disable-comment for it while still + # failing on anything warning-or-worse. + run: | + files=$(grep -lE '^#!.*/(env[[:space:]]+)?(ba)?sh([[:space:]]|$)' scripts/* 2>/dev/null) + echo "$files" | xargs nix develop -c shellcheck -S warning + prose-lint: name: prose lint (vale) runs-on: [hive-ci]