Skip to content

build(deps): bump kjanat/actionlint from 1.16.1 to 1.17.0 - #1453

Merged
mr-c merged 1 commit into
masterfrom
dependabot/github_actions/kjanat/actionlint-1.17.0
Sep 24, 2026
Merged

mr-c merged 1 commit into
masterfrom
dependabot/github_actions/kjanat/actionlint-1.17.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps kjanat/actionlint from 1.16.1 to 1.17.0.

Release notes

Sourced from kjanat/actionlint's releases.

v1.17.0

More of GitHub Actions understood. More mistakes caught before a workflow runs. actionlint 1.17.0 is a substantial release for this fork: explicit cache access controls, cache safety policies enabled by default, and a broad audit of workflow syntax, expressions, and local action manifests against GitHub's own schemas and runner code.

The schema work deserves equal billing. Valid expression-built matrices can now pass without spurious errors, newer workflow fields are understood, and malformed schedules and action metadata receive checks they previously escaped. Below are concrete examples of what changes when you upgrade, along with new installation options through the aqua registry and mise.

Upgrade note: the new policies can make previously clean workflows exit with status 1, including repositories without a configuration file. Existing opt-in policies retain their defaults.

Make cache access explicit

GitHub's cache-mode controls cache access independently of token permissions:

Mode Restore Save
read Yes No
write Yes Yes
write-only No Yes
none No No

Set it on the workflow or an individual job. Job settings override workflow settings; omission retains GitHub's trigger-dependent defaults. For example, give a reusable workflow a read-only ceiling:

on: pull_request_target
cache-mode: read
jobs:
report:
uses: $/.github/workflows/report.yml

actionlint follows nested local reusable calls and checks their explicit declarations against the caller's limit. Diagnostics preserve the original ./ or $/ reference. Missing or malformed callees are reported consistently regardless of file analysis order. (#163, #164)

Catch unsafe grants and ineffective cache steps

Three policies now run automatically:

  • cache-write-untrusted reports explicit write grants on low-trust triggers with access to default-branch caches, including pull_request_target, issue_comment, and workflow_run.
  • cache-call-unrestricted requires an explicit cache ceiling for reusable calls on those triggers.
  • cache-operation reports official actions/cache, actions/cache/save, and actions/cache/restore steps whose operations an explicit mode disables. Caller-imposed limits are followed through nested local workflows, including parallel child steps.

GitHub skips forbidden cache operations without failing the job. The operation check makes ineffective steps visible. The combined actions/cache action remains useful under read or write-only, where one operation is still available. Remote workflow bodies, wrappers, and package-manager caching options are not inspected. (#165)

For example, this job explicitly disables the operation its cache step requests:

jobs:
  build:
    runs-on: ubuntu-latest
    cache-mode: read
    steps:
      - uses: actions/cache/save@v6
</tr></table> 

... (truncated)

Changelog

Sourced from kjanat/actionlint's changelog.

Unreleased

  • Link CLI help to documentation at the release tag or development build's commit, including Go pseudo-versions and Makefile builds.
  • Add documented ACTIONLINT_* defaults for configuration selection, output, filters, logging and presentation. Split external-linter environment settings into literal BIN, argument FLAGS, and child ENV values for both ShellCheck and Pyflakes. Explicit flags override environment defaults, including empty and false values.
  • Pretty-print JSON metadata and JSON/SARIF diagnostics with installed jq when stdout is a terminal. Respect color controls and provide --json-pretty=false. Keep redirected output, JSONL, templates and stderr records unchanged; fall back to the original JSON if jq is unavailable or fails.
  • Make directory, configuration and executable paths in doctor clickable with OSC 8 file:// links. Follow the existing hyperlink controls and preserve JSON output. Encode special characters in link targets and support Windows drive and UNC paths.
  • Enable color automatically in GitHub Actions logs when GITHUB_ACTIONS=true. Respect NO_COLOR and explicit color controls, and keep automatic styling out of report files, structured output and custom templates.
  • Add OSC 8 links to the project name and URLs in CLI help. --hyperlinks=auto|always|never follows the [no-hyperlinks convention], including NO_HYPERLINKS and FORCE_HYPERLINKSkjanat/actionlint#65
  • Rebuild the CLI with a typed invocation model, a preserved Go flag parser for root calls, and Cobra commands for check, config inspection, rules, doctor, completion and version. Add JSON/JSONL/SARIF/GitHub output, template and output files, opt-in summaries, configuration origins and generated four-shell completion. Style terminal help while respecting color controls, add -V as a version alias, align doctor output, and keep concurrent verbose/debug log records intact. Preserve legacy options, templates, default diagnostics, version output, streams and exit codes. Test both grammars, command/file collisions and output side effects. Use the same input resolution, analysis results and renderers for commands and legacy Lint* methods. Preserve callbacks, working-directory handling and legacy write-error behavior. Protect all consumed local inputs from report replacement and retain configuration provenance through YAML merges. Move the frontend into internal/cli so library and Wasm builds do not import Cobra or pflag; Go callers migrating from the former root Command type can use the shared analysis APIs.
  • kjanat/actionlint#171

v1.17.0 - 2026-09-13

  • kjanat/actionlint#167

  • kjanat/actionlint#168

  • Upgrade note: the three new cache safety policies are enabled even without a configuration file and can make previously clean workflows exit with status 1. Disable individual checks with policy.cache-write-untrusted: false, policy.cache-call-unrestricted: false, or policy.cache-operation: falsekjanat/actionlint#165

  • Support current workflow schema fields and expression objects, including workflow descriptions, cancellation timeouts, image-version filters, stacked pull requests, empty choice options, disabled service images, and UTC timezone aliases.

  • Validate action manifests against generated runner schema constraints. Correct workflow expression contexts, matrix inference, function arity, expression depth, scalar decoding, required flags, schedule entries, and step ID checks.

  • Document the pinned workflow/action schema audit, complete definition coverage, regression evidence, and retained compatibility differences.

  • Enable cache safety policies by default: report explicit writes on low-trust triggers that can use default-branch caches, reusable calls without an explicit cache limit on those triggers, and official cache actions disabled by an explicit mode. Each policy can be disabled in configuration or suppressed on a specific line with a rule name and a reason.

  • Add policy.disallow-suppressions to prohibit inline cache exceptions for all or selected rules. Select report: suppression, violation, or allkjanat/actionlint#165

  • Support workflow- and job-level cache-mode values, including jobs that call reusable workflows. Check explicit cache access limits through nested local workflow calls, preserving job overrides and the distinction between omitted settings and nonekjanat/actionlint#163

  • kjanat/actionlint#164kjanat/actionlint#165)

[Changes][v1.17.0]

v1.16.1 - 2026-09-09

  • Report YAML alias type errors at each invalid alias use, with the anchor location included in the message. Preserve source locations inside anchored content and avoid missing-ref errors for malformed useskjanat/actionlint#149kjanat/actionlint#154)

  • kjanat/actionlint#150

  • kjanat/actionlint#151NixOS/nixpkgs#561437; thanks @​voidlily for the initial packaging proposal.)

  • kjanat/actionlint#151

... (truncated)

Commits
  • 08bb2c4 release: Prepare v1.17.0 distributions
  • 9098a85 Enforce cache safety policies by default with inline exceptions (#165)
  • 8991caa Support workflow and job cache access modes (#164)
  • 40ee367 funding: add sponsor badge
  • 231f09b Refresh the README demo for fork 1.16.1 and upstream 1.7.12 (#156)
  • 56c8ca1 Use nix profile add in installation docs
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [kjanat/actionlint](https://github.com/kjanat/actionlint) from 1.16.1 to 1.17.0.
- [Release notes](https://github.com/kjanat/actionlint/releases)
- [Changelog](https://github.com/kjanat/actionlint/blob/master/CHANGELOG.md)
- [Commits](kjanat/actionlint@662318d...08bb2c4)

---
updated-dependencies:
- dependency-name: kjanat/actionlint
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 23, 2026
@mr-c
mr-c enabled auto-merge (rebase) September 23, 2026 15:40
@mr-c
mr-c merged commit a54d8e2 into master Sep 24, 2026
147 checks passed
@mr-c
mr-c deleted the dependabot/github_actions/kjanat/actionlint-1.17.0 branch September 24, 2026 08:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant