fixes #40
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- | |
name: MegaLinter | |
on: # yamllint disable-line rule:truthy | |
push: null | |
pull_request: | |
branches: | |
- main | |
- master | |
permissions: read-all | |
env: | |
APPLY_FIXES: all | |
APPLY_FIXES_EVENT: all | |
APPLY_FIXES_MODE: pull_request | |
concurrency: | |
group: ${{ github.ref }}-${{ github.workflow }} | |
cancel-in-progress: true | |
jobs: | |
megalinter: | |
name: MegaLinter | |
runs-on: ubuntu-latest | |
permissions: | |
contents: write | |
issues: write | |
pull-requests: write | |
statuses: write | |
steps: | |
- name: Checkout Code | |
uses: actions/checkout@v4 | |
with: | |
token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} | |
fetch-depth: 0 | |
- name: MegaLinter | |
# kics-scan ignore-line | |
uses: oxsecurity/megalinter@latest | |
id: ml | |
env: | |
VALIDATE_ALL_CODEBASE: true | |
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
- name: Archive production artifacts | |
# kics-scan ignore-line | |
uses: actions/upload-artifact@v4 | |
if: success() || failure() | |
with: | |
name: MegaLinter reports | |
path: | | |
megalinter-reports | |
mega-linter.log | |
# Set APPLY_FIXES_IF var for use in future steps | |
- name: Set APPLY_FIXES_IF var | |
run: | | |
printf 'APPLY_FIXES_IF=%s\n' "${{ | |
steps.ml.outputs.has_updated_sources == 1 && | |
( | |
env.APPLY_FIXES_EVENT == 'all' || | |
env.APPLY_FIXES_EVENT == github.event_name | |
) && | |
( | |
github.event_name == 'push' || | |
github.event.pull_request.head.repo.full_name == github.repository | |
) | |
}}" >> "${GITHUB_ENV}" | |
# Set APPLY_FIXES_IF_* vars for use in future steps | |
- name: Set APPLY_FIXES_IF_* vars | |
run: | | |
printf 'APPLY_FIXES_IF_PR=%s\n' "${{ | |
env.APPLY_FIXES_IF == 'true' && | |
env.APPLY_FIXES_MODE == 'pull_request' | |
}}" >> "${GITHUB_ENV}" | |
printf 'APPLY_FIXES_IF_COMMIT=%s\n' "${{ | |
env.APPLY_FIXES_IF == 'true' && | |
env.APPLY_FIXES_MODE == 'commit' && | |
(!contains(fromJSON('["refs/heads/main", "refs/heads/master"]'), github.ref)) | |
}}" >> "${GITHUB_ENV}" | |
# Create pull request if applicable | |
# (for now works only on PR from the same repository, not from forks) | |
- name: Create Pull Request with applied fixes | |
# kics-scan ignore-line | |
uses: peter-evans/create-pull-request@v6 | |
id: cpr | |
if: env.APPLY_FIXES_IF_PR == 'true' | |
with: | |
token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }} | |
commit-message: "[MegaLinter] Apply linters automatic fixes" | |
title: "[MegaLinter] Apply linters automatic fixes" | |
labels: bot | |
- name: Create PR output | |
if: env.APPLY_FIXES_IF_PR == 'true' | |
run: | | |
echo "PR Number - ${{ steps.cpr.outputs.pull-request-number }}" | |
echo "PR URL - ${{ steps.cpr.outputs.pull-request-url }}" | |
# Push new commit if applicable | |
# (for now works only on PR from the same repository, not from forks) | |
- name: Prepare commit | |
if: env.APPLY_FIXES_IF_COMMIT == 'true' | |
run: sudo chown -Rc $UID .git/ | |
- name: Commit and push applied linter fixes | |
# kics-scan ignore-line | |
uses: stefanzweifel/git-auto-commit-action@latest | |
if: env.APPLY_FIXES_IF_COMMIT == 'true' | |
with: | |
branch: >- | |
${{ | |
github.event.pull_request.head.ref || | |
github.head_ref || | |
github.ref | |
}} | |
commit_message: "[MegaLinter] Apply linters fixes" |