Repository navigation
Appletini (4.0beta16)
Pre-release
Pre-release
Workflow linting moves into its own always-installed workflow, and Dependabot now sees the composite actions.
- New
.github/workflows/actions.ymlruns actionlint and zizmor, installed unconditionally likesecurity.yml. Previously these ran insideyaml.yml, which was gated on a file count that prunes.github— so a repo whose only YAML was its workflows got no workflow linting at all. That was 7 of 8 eustasy repos. yaml.ymlnow runs yamllint alone, and no longer triggers on paths yamllint is excluded from.- Fixed: Dependabot was watching none of the 23 composite actions, where every hash-pinned third-party action lives since 4.0beta13.
qltysh/qlty-actionandshivammathur/setup-phphad not been updatable since that release. - The test harness now asserts both that every deployed
.githubYAML is excluded from yamllint, and that every action directory is listed for Dependabot.