ci: trim shellcheck step comment, fail loudly on empty discovery

Move the SC2016 / -S warning rationale to the PR body — a decision
justification, not something that needs to live inline forever. Keep
only the one line that explains the non-obvious part of the code
itself: shebang-based discovery over a *.sh glob.

Also make the no-files case explicit: an empty match previously fell
through to shellcheck with no arguments (a confusing usage error, but
still non-zero); now it prints a clear message and exits 1.
This commit is contained in:
atlas 2026-09-16 00:06:01 +02:00
commit f4cabd117b

View file

@ -59,21 +59,17 @@ jobs:
shellcheck:
name: shellcheck
runs-on: [hive-ci]
# shellcheck itself is fast; nix shell's first pull of the closure is
# the slow part on a cold cache.
timeout-minutes: 10
steps:
- uses: actions/checkout@v3
- name: lint
# Discovers raw shell files by shebang rather than by extension —
# scripts/pre-push ships with no `.sh` suffix, so a `*.sh` glob
# would silently skip it (and any future extensionless script).
# -S warning drops info-level notes: the repo's one SC2016 hit is
# an intentionally single-quoted awk program, not a bug, and this
# keeps the gate free of a disable-comment for it while still
# failing on anything warning-or-worse.
# By shebang, not a `*.sh` glob — scripts/pre-push has no suffix.
run: |
files=$(grep -lE '^#!.*/(env[[:space:]]+)?(ba)?sh([[:space:]]|$)' scripts/* 2>/dev/null)
if [ -z "$files" ]; then
echo "no shell files discovered under scripts/ — check the shebang pattern" >&2
exit 1
fi
echo "$files" | xargs nix develop -c shellcheck -S warning
prose-lint: