mirror of
https://github.com/hadolint/hadolint-action.git
synced 2024-08-16 10:09:53 +02:00
Merge pull request #74 from ViacheslavKudinov/master
Fix of ShellCheck. Doc update. Int testing updates. Added ShellCheck job.
This commit is contained in:
commit
d292784f8f
3 changed files with 61 additions and 22 deletions
38
.github/workflows/ci.yml
vendored
38
.github/workflows/ci.yml
vendored
|
@ -8,6 +8,11 @@ on:
|
||||||
env:
|
env:
|
||||||
TEST_IMAGE_NAME: hadolint-action:${{github.sha}}
|
TEST_IMAGE_NAME: hadolint-action:${{github.sha}}
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
issues: write # Used by Release step to update "The automated release is failing" issue
|
||||||
|
pull-requests: write # Used by ShellCheck Action to add comments on PR
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
lint:
|
lint:
|
||||||
name: Lint
|
name: Lint
|
||||||
|
@ -18,10 +23,21 @@ jobs:
|
||||||
- name: Run hadolint
|
- name: Run hadolint
|
||||||
run: hadolint Dockerfile
|
run: hadolint Dockerfile
|
||||||
|
|
||||||
|
shellcheck:
|
||||||
|
name: ShellCheck
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v3
|
||||||
|
- name: Run ShellCheck
|
||||||
|
uses: reviewdog/action-shellcheck@v1.16.0
|
||||||
|
with:
|
||||||
|
reporter: github-pr-review
|
||||||
|
fail_on_error: true
|
||||||
|
|
||||||
build-test:
|
build-test:
|
||||||
name: Build and Test
|
name: Build and Test
|
||||||
runs-on: ubuntu-20.04
|
runs-on: ubuntu-20.04
|
||||||
needs: ["lint"]
|
needs: [ "lint", "shellcheck" ]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v3
|
- uses: actions/checkout@v3
|
||||||
- name: Build Docker image
|
- name: Build Docker image
|
||||||
|
@ -69,8 +85,9 @@ jobs:
|
||||||
failure-threshold: error
|
failure-threshold: error
|
||||||
format: json
|
format: json
|
||||||
|
|
||||||
- name: Run integration test 5 - output format
|
- name: Run integration test 5 - config file
|
||||||
# This step will never fail, but will print out rule violations.
|
# This step will never fail, but will print out rule violations
|
||||||
|
# because in config is set the error failure threshold.
|
||||||
id: hadolint5
|
id: hadolint5
|
||||||
uses: ./
|
uses: ./
|
||||||
with:
|
with:
|
||||||
|
@ -79,9 +96,20 @@ jobs:
|
||||||
|
|
||||||
- name: Run integration test 6 - verify results output parameter
|
- name: Run integration test 6 - verify results output parameter
|
||||||
# This step will never fail, but will print out the results from step5
|
# This step will never fail, but will print out the results from step5
|
||||||
run: echo "${{ steps.hadolint5.outputs.results }}"
|
env:
|
||||||
|
results: ${{ steps.hadolint5.outputs.results }}
|
||||||
|
run: echo "$results"
|
||||||
|
|
||||||
#- name: Run integration test 6 - output to file
|
- name: Run integration test 7 - set recursive
|
||||||
|
# This step will never fail, but will print out rule violations
|
||||||
|
# for all the Dockerfiles in repository.
|
||||||
|
uses: ./
|
||||||
|
with:
|
||||||
|
dockerfile: "*Dockerfile"
|
||||||
|
failure-threshold: error
|
||||||
|
recursive: true
|
||||||
|
|
||||||
|
#- name: Run integration test 8 - output to file
|
||||||
# # This step will never fail, but will print out rule violations.
|
# # This step will never fail, but will print out rule violations.
|
||||||
# uses: ./
|
# uses: ./
|
||||||
# with:
|
# with:
|
||||||
|
|
|
@ -28,10 +28,10 @@ steps:
|
||||||
| `dockerfile` | The path to the Dockerfile to be tested | `./Dockerfile` |
|
| `dockerfile` | The path to the Dockerfile to be tested | `./Dockerfile` |
|
||||||
| `recursive` | Search for specified dockerfile </br> recursively, from the project root | `false` |
|
| `recursive` | Search for specified dockerfile </br> recursively, from the project root | `false` |
|
||||||
| `config` | Custom path to a Hadolint config file | `./.hadolint.yaml` |
|
| `config` | Custom path to a Hadolint config file | `./.hadolint.yaml` |
|
||||||
| `output-file` | A sub-path where to save the </br> output as a file to | |
|
| `output-file` | A sub-path where to save the </br> output as a file to | `/dev/stdout` |
|
||||||
| `no-color` | Don't create colored output (`true`/`false`) | |
|
| `no-color` | Don't create colored output (`true`/`false`) | `false` |
|
||||||
| `no-fail` | Never fail the action (`true`/`false`) | |
|
| `no-fail` | Never fail the action (`true`/`false`) | `false` |
|
||||||
| `verbose` | Output more information (`true`/`false`) | |
|
| `verbose` | Output more information (`true`/`false`) | `false` |
|
||||||
| `format` | The output format. One of [`tty` \| `json` \| </br> `checkstyle` \| `codeclimate` \| </br> `gitlab_codeclimate` \| `codacy` \| `sarif`] | `tty` |
|
| `format` | The output format. One of [`tty` \| `json` \| </br> `checkstyle` \| `codeclimate` \| </br> `gitlab_codeclimate` \| `codacy` \| `sarif`] | `tty` |
|
||||||
| `failure-threshold` | Rule severity threshold for pipeline </br> failure. One of [`error` \| `warning` \| </br> `info` \| `style` \| `ignore`] | `info` |
|
| `failure-threshold` | Rule severity threshold for pipeline </br> failure. One of [`error` \| `warning` \| </br> `info` \| `style` \| `ignore`] | `info` |
|
||||||
| `override-error` | Comma separated list of rules to treat with `error` severity | |
|
| `override-error` | Comma separated list of rules to treat with `error` severity | |
|
||||||
|
|
37
hadolint.sh
37
hadolint.sh
|
@ -1,15 +1,18 @@
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
# The problem-matcher definition must be present in the repository
|
# The problem-matcher definition must be present in the repository
|
||||||
# checkout (outside the Docker container running hadolint). We copy
|
# checkout (outside the Docker container running hadolint). We copy
|
||||||
# problem-matcher.json to the home folder.
|
# problem-matcher.json to the home folder.
|
||||||
cp /problem-matcher.json "$HOME/"
|
|
||||||
|
|
||||||
|
PROBLEM_MATCHER_FILE="/problem-matcher.json"
|
||||||
|
if [ -f "$PROBLEM_MATCHER_FILE" ]; then
|
||||||
|
cp "$PROBLEM_MATCHER_FILE" "$HOME/"
|
||||||
|
fi
|
||||||
# After the run has finished we remove the problem-matcher.json from
|
# After the run has finished we remove the problem-matcher.json from
|
||||||
# the repository so we don't leave the checkout dirty. We also remove
|
# the repository so we don't leave the checkout dirty. We also remove
|
||||||
# the matcher so it won't take effect in later steps.
|
# the matcher so it won't take effect in later steps.
|
||||||
|
# shellcheck disable=SC2317
|
||||||
cleanup() {
|
cleanup() {
|
||||||
echo "::remove-matcher owner=brpaz/hadolint-action::"
|
echo "::remove-matcher owner=brpaz/hadolint-action::"
|
||||||
}
|
}
|
||||||
trap cleanup EXIT
|
trap cleanup EXIT
|
||||||
|
|
||||||
|
@ -20,19 +23,21 @@ if [ -n "$HADOLINT_CONFIG" ]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -z "$HADOLINT_TRUSTED_REGISTRIES" ]; then
|
if [ -z "$HADOLINT_TRUSTED_REGISTRIES" ]; then
|
||||||
unset HADOLINT_TRUSTED_REGISTRIES;
|
unset HADOLINT_TRUSTED_REGISTRIES
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
COMMAND="hadolint $HADOLINT_CONFIG"
|
||||||
|
|
||||||
if [ "$HADOLINT_RECURSIVE" = "true" ]; then
|
if [ "$HADOLINT_RECURSIVE" = "true" ]; then
|
||||||
shopt -s globstar
|
shopt -s globstar
|
||||||
|
|
||||||
filename="${!#}"
|
filename="${!#}"
|
||||||
flags="${@:1:$#-1}"
|
flags="${*:1:$#-1}"
|
||||||
|
|
||||||
RESULTS=$(hadolint $HADOLINT_CONFIG $flags **/$filename)
|
RESULTS=$(eval "$COMMAND $flags" -- **/"$filename")
|
||||||
else
|
else
|
||||||
# shellcheck disable=SC2086
|
flags=$*
|
||||||
RESULTS=$(hadolint $HADOLINT_CONFIG "$@")
|
RESULTS=$(eval "$COMMAND" "$flags")
|
||||||
fi
|
fi
|
||||||
FAILED=$?
|
FAILED=$?
|
||||||
|
|
||||||
|
@ -40,16 +45,22 @@ if [ -n "$HADOLINT_OUTPUT" ]; then
|
||||||
if [ -f "$HADOLINT_OUTPUT" ]; then
|
if [ -f "$HADOLINT_OUTPUT" ]; then
|
||||||
HADOLINT_OUTPUT="$TMP_FOLDER/$HADOLINT_OUTPUT"
|
HADOLINT_OUTPUT="$TMP_FOLDER/$HADOLINT_OUTPUT"
|
||||||
fi
|
fi
|
||||||
echo "$RESULTS" > $HADOLINT_OUTPUT
|
echo "$RESULTS" >"$HADOLINT_OUTPUT"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
RESULTS="${RESULTS//$'\\n'/''}"
|
RESULTS="${RESULTS//$'\\n'/''}"
|
||||||
|
|
||||||
echo "results<<EOF" >> $GITHUB_OUTPUT
|
{
|
||||||
echo "${RESULTS}" >> $GITHUB_OUTPUT
|
echo "results<<EOF"
|
||||||
echo "EOF" >> $GITHUB_OUTPUT
|
echo "$RESULTS"
|
||||||
|
echo "EOF"
|
||||||
|
} >>"$GITHUB_OUTPUT"
|
||||||
|
|
||||||
{ echo "HADOLINT_RESULTS<<EOF"; echo "$RESULTS"; echo "EOF"; } >> $GITHUB_ENV
|
{
|
||||||
|
echo "HADOLINT_RESULTS<<EOF"
|
||||||
|
echo "$RESULTS"
|
||||||
|
echo "EOF"
|
||||||
|
} >>"$GITHUB_ENV"
|
||||||
|
|
||||||
[ -z "$HADOLINT_OUTPUT" ] || echo "Hadolint output saved to: $HADOLINT_OUTPUT"
|
[ -z "$HADOLINT_OUTPUT" ] || echo "Hadolint output saved to: $HADOLINT_OUTPUT"
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue