ci: vendor validation scripts and remove remote action pins #57
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: MPL-2.0 | |
| # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk> | |
| # | |
| # Estate Rules — enforces hyperpolymath estate-wide conventions: | |
| # * root shape (allowlist of permitted root entries) | |
| # * AsciiDoc-by-default (no .md files under docs/) | |
| # * zig is banned (no zig scaffolding or references) | |
| # | |
| # Each rule is enforced by an executable check script under scripts/. Failures | |
| # are surfaced as workflow errors so the rule can't silently regress. | |
| name: Estate Rules | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| permissions: | |
| actions: read | |
| contents: read | |
| jobs: | |
| estate-rules: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Root shape allowlist | |
| run: bash scripts/check-root-shape.sh . | |
| - name: AsciiDoc by default (no .md under docs/) | |
| run: bash scripts/check-no-md-in-docs.sh . |