Skip to content

[tool] Update skills_lint to ^0.5.2 and add SARIF code scanning - #50

Merged
kevmoo merged 1 commit into
kevmoo:mainfrom
reidbaker-agent:skills-lint-0.5.2
Sep 18, 2026
Merged

kevmoo merged 1 commit into
kevmoo:mainfrom
reidbaker-agent:skills-lint-0.5.2

Conversation

@reidbaker-agent

@reidbaker-agent reidbaker-agent commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

I dont know if you want the comments in prs that edit skills. If you dont just close this pr and update on your own schedule.

Details ## Summary
  • Bump skills_lint dev_dependency in tool/pubspec.yaml to ^0.5.2.
  • Add .github/workflows/code_scanning.yaml to run skills_lint --format=sarif and upload SARIF diagnostic reports to GitHub Code Scanning.

Workflow Details

  • Triggers: On pull requests and pushes to main touching .agents/**, skills/**, tool/**, or .github/workflows/code_scanning.yaml.
  • Permissions: contents: read at workflow level; contents: read and security-events: write for the sarif_scan job.
  • SARIF Generation: Runs dart run skills_lint --format=sarif from tool/, leveraging 0.5.2's config-relative path resolution (tool/skills_lint.yaml -> ../skills).
  • Upload: Uploads via github/codeql-action/upload-sarif with category skills_lint, guarded against fork PRs where security-events: write is unavailable.
  • Gate: Enforces exit code check on linter status so PR checks fail if violations exist.

Verification

  • Tested config-relative path resolution empirically from tool/ with dart run skills_lint.
  • Verified local SARIF generation and validated SARIF 2.1.0 JSON format.
  • Ran dart format . (clean).
  • Ran dart analyze --fatal-infos tool/ (0 issues).
  • Ran unit and validation tests via dart test (all passed).

- Bump skills_lint dev_dependency to ^0.5.2 in tool/pubspec.yaml.
- Add .github/workflows/code_scanning.yaml to run skills_lint and upload SARIF reports to GitHub Code Scanning.
@reidbaker
reidbaker requested a review from kevmoo September 18, 2026 21:48
@reidbaker
reidbaker marked this pull request as ready for review September 18, 2026 21:50
@kevmoo
kevmoo merged commit cc484f4 into kevmoo:main Sep 18, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants