Repository navigation
fix(ci): 🔧 markdownlint を npm 経由実行へ再切替し startup_failure を再発防止 - #62
Conversation
PR #44 で導入した npm 経由実行が PR #55 で action 利用に戻され、その後 DavidAnson/markdownlint-cli2-action が allowed_actions の patterns_allowed に 含まれない状態で 5/21 以降 8 連続 startup_failure になっていた。 genzouw.com の terraform 側 (commit f5af9f3) で patterns_allowed に DavidAnson/markdownlint-cli2-action@* を追加して既に対応済みだが、 許可リストへの依存自体がフラジャイル (パターン削除や repo 設定更新ミスで 即時 startup_failure に戻る) ため、npm install による markdownlint-cli2 実行へ戻して許可リストに依存しない構成にする。 - actions/setup-node@v6.4.0 で Node.js 20.19 をセットアップ - npm install -g --ignore-scripts markdownlint-cli2@0.22.1 でインストール - markdownlint-cli2 を直接実行 - 経緯と意図をコメントとして workflow に明記し、再々度の差し戻しを防ぐ
Qodo reviews are paused for this user.Troubleshooting steps vary by plan Learn more → On a Teams plan? Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center? |
|
Warning Review limit reached
More reviews will be available in 16 minutes and 47 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
Up to standards ✅🟢 Issues
|
Summary
startup_failureの markdownlint workflow を、PR fix(ci): 🔧 markdownlint を npm 経由実行に切り替えて startup_failure を解消 #44 と同じ npm 経由実行へ戻して復旧するDavidAnson/markdownlint-cli2-actionを撤去し、allowed_actions(patterns_allowed) への依存をワークフロー側から排除する失敗 Run
https://github.com/genzouw/kakezan-manabo/actions/runs/26388299802 (
startup_failure、ジョブ 0 件)5/21 (PR #55) で action 利用へ戻して以降、
gh run list --workflow markdownlint.ymlの通り直近 8 回連続でstartup_failure。原因
DavidAnson/markdownlint-cli2-actionは third-party の Marketplace action。本リポジトリの
allowed_actionsはselected+github_owned_allowed=true+verified_allowed=trueで運用しており、patterns_allowedに登録されていない third-party action は SHA pin していても起動拒否 (startup_failure) となる。PR #44 ではまさにこの事象を解消するため npm 経由実行へ切り替えたが、PR #55 で action 利用へ意図せず差し戻されていた。
(非公開リポジトリ)側の terraform (commitf5af9f3、2026-05-26) でDavidAnson/markdownlint-cli2-action@*をpatterns_allowedに追加して GitHub 側の許可は復旧済みだが、許可リストへの依存自体が壊れやすい構造のため、ワークフロー側でも依存を取り除く。変更内容
actions/setup-node@v6.4.0で Node.js20.19をセットアップ (他 workflow と統一)npm install -g --no-fund --no-audit --ignore-scripts markdownlint-cli2@0.22.1でインストール--ignore-scripts: postinstall 経由の任意コード実行を防止markdownlint-cli2 --config .markdownlint-cli2.jsonc "**/*.md"を直接実行continue-on-error: trueは既存方針 (MD040/MD031 整理後に外す) に従い据え置きTerraform 側について
genzouw.comのactions_patterns_allowedでDavidAnson/markdownlint-cli2-action@*は既に許可されている状態。本 PR では terraform は変更しない。将来このパターンを掃除する場合、本 workflow に依存が無いことを確認してから削除可能。
Test plan
pull_requestイベントで markdownlint workflow がstartup_failureせず起動するmarkdownlint-cli2が実行され、レポートが出力される (継続失敗時もcontinue-on-errorで全体は通る)actionlintが通る