# Linting Workflows With actionlint — GitHub Actions

Source: https://www.skillbyai.com/en/github-actions/p-lint

> Catch errors before pushing.

## Static checks for workflow files

Workflow errors normally appear only after you push and wait for a run. **actionlint** checks workflows locally and in CI: YAML syntax, unknown keys, invalid cron, undefined matrix properties and outputs, job dependency errors, permission scopes, action inputs for popular actions, and script injection risks; with shellcheck installed it also lints shell scripts in run steps. Add it as a CI job or pre-commit hook. Every lint result in this course came from running it.

## Keep workflows healthy

Lint workflows in CI, debug failing runs efficiently, and review with a checklist.

![Three ideas: linting, debugging, checklist.](assets/figures/github-actions/section-8-map.svg) — Figure 8.1 — Linting, debugging and checklist.

## Running actionlint in CI

Not linted or run here; check the GitHub Actions documentation for current syntax.

```yaml
jobs:
  actionlint:
    runs-on: ubuntu-latest
    permissions: { contents: read }
    steps:
      - uses: actions/checkout@v4
      - name: Lint workflows
        run: |
          bash <(curl -sSfL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
          ./actionlint -color
```

## Lint locally before pushing

Running actionlint before each push avoids the slow push-wait-fix loop for typos.

**Quiz:** Which mistake can actionlint catch without running the workflow?

- [x] A needs: reference to a job that does not exist
- [ ] A failing unit test
- [ ] A slow network
- [ ] An expired cloud credential

*Answer:* A needs: reference to a job that does not exist. Static analysis of workflow files.
