Skip to content

CI: switch to kjanat/actionlint v1.17.0 - #259

Open
kolyshkin wants to merge 1 commit into
moby:mainfrom
kolyshkin:actionlint-kjanat-v1.16.0
Open

kolyshkin wants to merge 1 commit into
moby:mainfrom
kolyshkin:actionlint-kjanat-v1.16.0

Conversation

@kolyshkin

@kolyshkin kolyshkin commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

The devops-actions/actionlint wrapper runs an old rhysd/actionlint
release. Use the maintained kjanat/actionlint fork's own action instead,
pinned to the commit that pins its container image by digest (as
recommended by its README; the release tag itself references the image
by a floating tag).

Since v1.17.0 knows about the ubuntu-26.04 runner label, the
self-hosted-runner escape hatch in .github/actionlint.yaml is no
longer needed, so drop it.

Checked locally with the v1.17.0 binary (the same one the action's
container runs), without .github/actionlint.yaml: no findings.

@kolyshkin
kolyshkin force-pushed the actionlint-kjanat-v1.16.0 branch from 1ee9fac to 0a03165 Compare September 9, 2026 17:50
The devops-actions/actionlint wrapper runs an old rhysd/actionlint
release. Use the maintained kjanat/actionlint fork's own action
instead, pinned to the commit that pins its image by digest.

Since v1.17.0 knows about the ubuntu-26.04 runner label, the
self-hosted-runner escape hatch in .github/actionlint.yaml is no
longer needed, so drop it.

Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
@kolyshkin
kolyshkin force-pushed the actionlint-kjanat-v1.16.0 branch from 0a03165 to 273083b Compare October 5, 2026 06:28
@kolyshkin kolyshkin changed the title CI: switch to kjanat/actionlint v1.16.0 CI: switch to kjanat/actionlint v1.17.0 Oct 5, 2026
@kolyshkin
kolyshkin requested review from thaJeztah and vvoland October 5, 2026 06:31
with:
persist-credentials: false
- uses: devops-actions/actionlint@ec02b36684b2f574f1d219ad0a43b082e46bf3e4 # v0.1.13
- uses: kjanat/actionlint@722799fa4b8cc6734debb97bae24aca9e0dbaf59 # v1.17

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this should use v1.17.0 (instead of v1.17, which may be a rolling tag?)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In fact it's better to use v1.17 here. The v1.17 tag points to the commit right after the release (722799f, "pin the action image of v1.17.0 to its digest"), which pins the image by digest. That is what the upstream README recommends ("For an immutable action reference with a pinned image, use the full commit SHA resolved from a floating tag").

Since we pin by SHA anyway, the rolling nature of v1.17 doesn't matter here — the comment just says which tag the SHA was resolved from.

@thaJeztah thaJeztah Oct 7, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but v1.17.0 is an immutable tag, and signed.

If the floating v1.17 tag is updated, there's no way to verify if the commit we picked was ever matching that release.

IMG_2840

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

technically, for the immutable tags, we wouldn't even need to pin to a sha (they can't be updated, unless github itself is compromised)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See, the issue here is, if we use v1.17.0 (or its sha, doesn't matter), the docker image used by the action is not pinned to a sha (which is what kjanat/actionlint@722799f fixes).

Which is understandable: the author sets a tag, builds a docker image, uploads it and only after that they can pin docker image to a sha. Chicken-and-egg problem here and the solution is rolling tag (which we pin to a sha so it's not a problem).

If you're OK with using unpinned docker image from an action, AND zizmor knows about immutable tags and thus won't complan about v1.17.0, I'm happy to change the above to

- uses: kjanat/actionlint@v1.17.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wait, but does the action run an image, or the action itself?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

oh! the action is just a wrapper for an image that runs the actual work 🤔

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So now when we figured this out they've moved away from docker image (in kjanat/actionlint#185) so for the next version (1.18 or 2.0, I dunno) we will need a specific non-floating tag (and if the tag is immutable, we can drop sha, hope zizmor knows about immutable tags).

So this can be merged as is for now and I'm not adding a comment about v1.17.0 vs v1.17.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants