Skip to content

Switch actionlint to the kjanat fork, v1.17.0 - #113

Merged
roryabraham merged 1 commit into
mainfrom
rory/actionlint-fork
Sep 22, 2026
Merged

roryabraham merged 1 commit into
mainfrom
rory/actionlint-fork

Conversation

@roryabraham

Copy link
Copy Markdown
Contributor

Details

Switches the actionlint we run on every PR in the org from rhysd/actionlint v1.7.11 to the maintained fork, kjanat/actionlint v1.17.0. Upstream has stalled (latest release v1.7.12, ~190 open issues) and its schema predates keys GitHub has since added, so valid workflows fail our check. Tracked in https://github.com/Expensify/Expensify/issues/678960, which also has the audit of the fork.

Three changes:

  • scripts/actionlint.sh downloads from kjanat/actionlint releases. The asset naming (actionlint_<version>_<os>_<arch>.tar.gz) is unchanged, so the checksums-file parsing is untouched. The fork prints its version as actionlint.kjanat.dev 1.17.0 rather than the bare version upstream prints, so the cached-binary check now matches on the version number instead of the whole first line.
  • scripts/actionlint_checksums.txt replaced with the v1.17.0 checksums. I dropped the .sbom.json lines the fork appends to its checksums file, since the script greps that file for the tarball name and would otherwise match them too.
  • Removed the concurrency.queue suppression from .github/actionlint.yml. The fork accepts the key, and nothing in the org uses it yet.

Merge order

This must merge before the 13 follow-up PRs, and it will turn the actionlint check red on them until they merge. The fork adds a cache-call-unrestricted check that flags a reusable workflow call from a pull_request_target, issue_comment, or issues trigger with no cache-mode. Those PRs set cache-mode: read on the affected calls, but that key is not in v1.7.11's schema, so they cannot merge first. Merge this, then merge the follow-ups immediately:

I ran the fork against all 152 non-archived repos in the org. 46 of the 74 with workflows pass clean. The 13 above are the only actively maintained repos the new check fails, and each fails only on these reusable workflow calls. The rest are upstream forks we do not actively maintain (retired actions/* versions and the node20 runtime deprecation), which this leaves as is.

Related Issues

https://github.com/Expensify/Expensify/issues/678960

Manual Tests

Ran the modified scripts/actionlint.sh end to end: it downloads the v1.17.0 darwin/arm64 tarball, the checksum matches, it reports actionlint.kjanat.dev 1.17.0, and a second run finds the cached binary instead of re-downloading. Ran the installed binary against this repo's workflows with the updated config; they pass.

rhysd/actionlint has stalled at v1.7.11 and its schema predates keys GitHub
has since added, so valid workflows fail our check. The kjanat fork is the
maintained continuation and keeps the release asset naming our script parses.

The fork prints its version as "actionlint.kjanat.dev 1.17.0", so the cached
binary check now matches on the version number rather than the whole first line.
Drop the concurrency.queue suppression, which the fork no longer needs.
@roryabraham
roryabraham marked this pull request as ready for review September 22, 2026 05:44
@roryabraham
roryabraham merged commit 1d42bc9 into main Sep 22, 2026
7 of 8 checks passed
@roryabraham
roryabraham deleted the rory/actionlint-fork branch September 22, 2026 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants