Skip to content

ci(trunk): install actionlint before custom lint command - #542

Merged
KooshaPari merged 1 commit into
mainfrom
fix/trunk-actionlint-setup-20260808
Aug 8, 2026
Merged

KooshaPari merged 1 commit into
mainfrom
fix/trunk-actionlint-setup-20260808

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Aug 8, 2026 •

Copy link
Copy Markdown
Owner

User description

Summary

  • install the official actionlint binary before trunk-action
  • add it to PATH for the custom .trunk/trunk.yaml command

Evidence

Run 31237292485 failed because trunk reported Unable to find binary in PATH for actionlint; the workflow had no setup-deps step and trunk custom commands do not provision binaries.

Validation: git diff --check; workflow content inspected.

Airlock: no snapshot needed after commit (clean tree).


CodeAnt-AI Description

Ensure trunk checks can run actionlint in CI

What Changed

  • CI now installs actionlint before running the repository’s trunk checks
  • The installed tool is added to the workflow path and verified before linting starts
  • Pull requests no longer fail with a misleading “Binary not found” error when trunk invokes actionlint

Impact

✅ Fewer CI lint failures
✅ Reliable workflow validation
✅ Clearer setup errors

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Chores
    • Added automated installation and verification of the latest workflow linting tool before Trunk Check runs.
    • Improved reliability of workflow validation in CI.

Copilot AI lite review requested due to automatic review settings August 8, 2026 04:03
@codeant-ai

codeant-ai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 2d612bb Aug 08, 2026 · 04:03 04:04

@codeant-ai

codeant-ai Bot commented Aug 8, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

L17 Latency Budget Report

--- Latency Budget Summary ---
  Total endpoints checked: 0
  Passed: 0
  Warnings: 0
  Failures: 0

Checked against: budgets/rest-endpoints.yaml.

@codeant-ai codeant-ai Bot added the size:S This PR changes 10-29 lines, ignoring generated files label Aug 8, 2026
run: |
set -euo pipefail
mkdir -p "$HOME/.local/bin"
bash <(curl -fsSL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash) latest "$HOME/.local/bin"
@coderabbitai

coderabbitai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key: "review"
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 48cfd16d-3cfa-42ef-9199-c80502f836cd

📥 Commits

Reviewing files that changed from the base of the PR and between 0cbeb28 and 2d612bb.

📒 Files selected for processing (1)
  • .github/workflows/trunk-check.yml

📝 Walkthrough

Walkthrough

The Trunk Check workflow now installs the latest actionlint binary, adds it to the GitHub Actions path, and verifies its version before Trunk Check runs.

Changes

Trunk Check workflow

Layer / File(s) Summary
Install and expose actionlint
.github/workflows/trunk-check.yml
The workflow downloads actionlint into $HOME/.local/bin, adds that directory to GITHUB_PATH, and verifies the installed version before Trunk Check.

Estimated code review effort: 2 (Simple) | ~5 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the change and validation, but it omits most template sections, including related issues, test status, coverage notes, reviewer notes, and the 71-pillar self-check. Add the missing template sections and record applicable checklist results, test information, coverage notes, reviewer guidance, and 71-pillar impact.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes installing actionlint for the Trunk CI command.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/trunk-actionlint-setup-20260808

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

L17 Latency Regression Report

No trace file available — cannot compute regression

Threshold: 10% p99 regression.

@sonarqubecloud

sonarqubecloud Bot commented Aug 8, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
E Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2d612bb982

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

run: |
set -euo pipefail
mkdir -p "$HOME/.local/bin"
bash <(curl -fsSL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash) latest "$HOME/.local/bin"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pin the actionlint installer

In this pull_request/push workflow, this line executes whatever is currently on the upstream rhysd/actionlint main branch and asks it to install latest, while the adjacent actions are pinned to SHAs. A transient or compromised upstream change can break CI or run arbitrary code in this job without any repository change, so fetch a fixed actionlint release and ideally verify its checksum, or pin the installer to a commit.

Useful? React with 👍 / 👎.

@kilo-code-bot

kilo-code-bot Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No New Issues Found | Recommendation: Merge

Files Reviewed (1 file)
  • .github/workflows/trunk-check.yml

Reviewed by step-3.7-flash · Input: 90.3K · Output: 9.3K · Cached: 322.4K

@KooshaPari
KooshaPari merged commit 3da3564 into main Aug 8, 2026
31 of 39 checks passed
@KooshaPari
KooshaPari deleted the fix/trunk-actionlint-setup-20260808 branch August 8, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants