Switch actionlint to the kjanat fork, v1.17.0 - #113
Merged
Merged
Conversation
rhysd/actionlint has stalled at v1.7.11 and its schema predates keys GitHub has since added, so valid workflows fail our check. The kjanat fork is the maintained continuation and keeps the release asset naming our script parses. The fork prints its version as "actionlint.kjanat.dev 1.17.0", so the cached binary check now matches on the version number rather than the whole first line. Drop the concurrency.queue suppression, which the fork no longer needs.
roryabraham
marked this pull request as ready for review
September 22, 2026 05:44
This was referenced Sep 22, 2026
[No QA] Set cache-mode: read on reusable workflow calls from low-trust triggers
Expensify/App#101846
Merged
Merged
AndrewGable
approved these changes
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Details
Switches the actionlint we run on every PR in the org from
rhysd/actionlintv1.7.11 to the maintained fork,kjanat/actionlintv1.17.0. Upstream has stalled (latest release v1.7.12, ~190 open issues) and its schema predates keys GitHub has since added, so valid workflows fail our check. Tracked in https://github.com/Expensify/Expensify/issues/678960, which also has the audit of the fork.Three changes:
scripts/actionlint.shdownloads fromkjanat/actionlintreleases. The asset naming (actionlint_<version>_<os>_<arch>.tar.gz) is unchanged, so the checksums-file parsing is untouched. The fork prints its version asactionlint.kjanat.dev 1.17.0rather than the bare version upstream prints, so the cached-binary check now matches on the version number instead of the whole first line.scripts/actionlint_checksums.txtreplaced with the v1.17.0 checksums. I dropped the.sbom.jsonlines the fork appends to its checksums file, since the script greps that file for the tarball name and would otherwise match them too.concurrency.queuesuppression from.github/actionlint.yml. The fork accepts the key, and nothing in the org uses it yet.Merge order
This must merge before the 13 follow-up PRs, and it will turn the actionlint check red on them until they merge. The fork adds a
cache-call-unrestrictedcheck that flags a reusable workflow call from apull_request_target,issue_comment, orissuestrigger with nocache-mode. Those PRs setcache-mode: readon the affected calls, but that key is not in v1.7.11's schema, so they cannot merge first. Merge this, then merge the follow-ups immediately:I ran the fork against all 152 non-archived repos in the org. 46 of the 74 with workflows pass clean. The 13 above are the only actively maintained repos the new check fails, and each fails only on these reusable workflow calls. The rest are upstream forks we do not actively maintain (retired
actions/*versions and the node20 runtime deprecation), which this leaves as is.Related Issues
https://github.com/Expensify/Expensify/issues/678960
Manual Tests
Ran the modified
scripts/actionlint.shend to end: it downloads the v1.17.0 darwin/arm64 tarball, the checksum matches, it reportsactionlint.kjanat.dev 1.17.0, and a second run finds the cached binary instead of re-downloading. Ran the installed binary against this repo's workflows with the updated config; they pass.