Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot <copilot@github.com>
22 lines
469 B
YAML
22 lines
469 B
YAML
name: Lint Markdown files
|
|
|
|
on:
|
|
pull_request:
|
|
types: [ "opened", "reopened", "synchronize" ]
|
|
push:
|
|
branches: [ '**' ]
|
|
tags-ignore: [ '**' ]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
markdown-lint:
|
|
runs-on:
|
|
- ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- uses: DavidAnson/markdownlint-cli2-action@ded1f9488f68a970bc66ea5619e13e9b52e601cd # v23.2.0
|
|
with:
|
|
globs: '**/*.md'
|