diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index 57577b3b..fc4ec447 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -59,21 +59,17 @@ jobs: shellcheck: name: shellcheck runs-on: [hive-ci] - # shellcheck itself is fast; nix shell's first pull of the closure is - # the slow part on a cold cache. timeout-minutes: 10 steps: - uses: actions/checkout@v3 - name: lint - # Discovers raw shell files by shebang rather than by extension — - # scripts/pre-push ships with no `.sh` suffix, so a `*.sh` glob - # would silently skip it (and any future extensionless script). - # -S warning drops info-level notes: the repo's one SC2016 hit is - # an intentionally single-quoted awk program, not a bug, and this - # keeps the gate free of a disable-comment for it while still - # failing on anything warning-or-worse. + # By shebang, not a `*.sh` glob — scripts/pre-push has no suffix. run: | files=$(grep -lE '^#!.*/(env[[:space:]]+)?(ba)?sh([[:space:]]|$)' scripts/* 2>/dev/null) + if [ -z "$files" ]; then + echo "no shell files discovered under scripts/ — check the shebang pattern" >&2 + exit 1 + fi echo "$files" | xargs nix develop -c shellcheck -S warning prose-lint: