पाठ 23 / 25

Linting Workflows With actionlint

Catch errors before pushing.

Static checks for workflow files

Workflow errors normally appear only after you push and wait for a run. actionlint checks workflows locally and in CI: YAML syntax, unknown keys, invalid cron, undefined matrix properties and outputs, job dependency errors, permission scopes, action inputs for popular actions, and script injection risks; with shellcheck installed it also lints shell scripts in run steps. Add it as a CI job or pre-commit hook. Every lint result in this course came from running it.

Keep workflows healthy

Lint workflows in CI, debug failing runs efficiently, and review with a checklist.

Three ideas: linting, debugging, checklist.
Figure 8.1 — Linting, debugging and checklist.

Running actionlint in CI

Not linted or run here; check the GitHub Actions documentation for current syntax.

jobs:
  actionlint:
    runs-on: ubuntu-latest
    permissions: { contents: read }
    steps:
      - uses: actions/checkout@v4
      - name: Lint workflows
        run: |
          bash <(curl -sSfL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
          ./actionlint -color

Lint locally before pushing

Running actionlint before each push avoids the slow push-wait-fix loop for typos.

त्वरित जाँच: Which mistake can actionlint catch without running the workflow?

  • A needs: reference to a job that does not exist
  • A failing unit test
  • A slow network
  • An expired cloud credential
Answer

A needs: reference to a job that does not exist — Static analysis of workflow files.