name: ShellCheck # Every file in this repository is a shell script that people are # invited to run as root, so a lint gate is the cheapest guard against # the class of bug that keeps showing up here: unquoted expansions, # values interpolated into commands, and exit statuses that go unchecked. on: push: branches: [main] pull_request: workflow_dispatch: permissions: contents: read jobs: shellcheck: name: ShellCheck runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Run ShellCheck uses: ludeeus/action-shellcheck@master with: # warning, not error: the first run at this level surfaced # exactly two findings and both were fixed, so there is no # pre-existing backlog to grandfather in. Anything new that # trips it is genuinely new. Dropping to the default (info) # would also pull in style suggestions across every script -- # worth doing, but as its own pass. severity: warning check_together: 'yes' format: gcc