Skip to content

fix(ci): 🔧 markdownlint を npm 経由実行へ再切替し startup_failure を再発防止 - #62

Merged
genzouw merged 1 commit into
mainfrom
fix/markdownlint-npm-restore
May 29, 2026
Merged

genzouw merged 1 commit into
mainfrom
fix/markdownlint-npm-restore

Conversation

@genzouw

@genzouw genzouw commented May 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

失敗 Run

https://github.com/genzouw/kakezan-manabo/actions/runs/26388299802 (startup_failure、ジョブ 0 件)

5/21 (PR #55) で action 利用へ戻して以降、gh run list --workflow markdownlint.yml の通り直近 8 回連続で startup_failure。

原因

DavidAnson/markdownlint-cli2-action は third-party の Marketplace action。
本リポジトリの allowed_actions は selected + github_owned_allowed=true + verified_allowed=true で運用しており、patterns_allowed に登録されていない third-party action は SHA pin していても起動拒否 (startup_failure) となる。

PR #44 ではまさにこの事象を解消するため npm 経由実行へ切り替えたが、PR #55 で action 利用へ意図せず差し戻されていた。

(非公開リポジトリ) 側の terraform (commit f5af9f3、2026-05-26) で DavidAnson/markdownlint-cli2-action@* を patterns_allowed に追加して GitHub 側の許可は復旧済みだが、許可リストへの依存自体が壊れやすい構造のため、ワークフロー側でも依存を取り除く。

変更内容

  • actions/setup-node@v6.4.0 で Node.js 20.19 をセットアップ (他 workflow と統一)
  • npm install -g --no-fund --no-audit --ignore-scripts markdownlint-cli2@0.22.1 でインストール
    • --ignore-scripts: postinstall 経由の任意コード実行を防止
  • markdownlint-cli2 --config .markdownlint-cli2.jsonc "**/*.md" を直接実行
  • continue-on-error: true は既存方針 (MD040/MD031 整理後に外す) に従い据え置き
  • 経緯と意図を workflow に日本語コメントで明記

Terraform 側について

genzouw.com の actions_patterns_allowed で DavidAnson/markdownlint-cli2-action@* は既に許可されている状態。本 PR では terraform は変更しない。

将来このパターンを掃除する場合、本 workflow に依存が無いことを確認してから削除可能。

Test plan

  • 本 PR の pull_request イベントで markdownlint workflow が startup_failure せず起動する
  • markdownlint-cli2 が実行され、レポートが出力される (継続失敗時も continue-on-error で全体は通る)
  • actionlint が通る

PR #44 で導入した npm 経由実行が PR #55 で action 利用に戻され、その後
DavidAnson/markdownlint-cli2-action が allowed_actions の patterns_allowed に
含まれない状態で 5/21 以降 8 連続 startup_failure になっていた。

genzouw.com の terraform 側 (commit f5af9f3) で patterns_allowed に
DavidAnson/markdownlint-cli2-action@* を追加して既に対応済みだが、
許可リストへの依存自体がフラジャイル (パターン削除や repo 設定更新ミスで
即時 startup_failure に戻る) ため、npm install による
markdownlint-cli2 実行へ戻して許可リストに依存しない構成にする。

- actions/setup-node@v6.4.0 で Node.js 20.19 をセットアップ
- npm install -g --ignore-scripts markdownlint-cli2@0.22.1 でインストール
- markdownlint-cli2 を直接実行
- 経緯と意図をコメントとして workflow に明記し、再々度の差し戻しを防ぐ
@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@coderabbitai

coderabbitai Bot commented May 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@genzouw, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 16 minutes and 47 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d6f0156d-45d7-452c-b048-b45f5abc8bd1

📥 Commits

Reviewing files that changed from the base of the PR and between b299464 and 6dad3d5.

📒 Files selected for processing (1)
  • .github/workflows/markdownlint.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/markdownlint-npm-restore

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@genzouw
genzouw merged commit 3808e03 into main May 29, 2026
14 checks passed
@genzouw
genzouw deleted the fix/markdownlint-npm-restore branch May 29, 2026 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant