koalaman/shellcheck:stable is built FROM scratch with shellcheck as the entrypoint and no /bin/sh, so the runner cannot start a job script in it and the job fails with an OCI runtime error before shellcheck ever runs. The -alpine variant is the same tool with a shell around it.
28 lines
1.3 KiB
YAML
28 lines
1.3 KiB
YAML
# CI on the self-hosted GitLab, ported from .github/workflows/shellcheck.yml
|
|
# when the GitHub account was suspended on 2026-09-20. The Actions file stays
|
|
# in the tree as the reference.
|
|
#
|
|
# ludeeus/action-shellcheck has no GitLab equivalent, so this runs shellcheck
|
|
# directly from its own digest-pinned image and reproduces the settings the
|
|
# action was given: severity=warning, gcc format, every script in one run.
|
|
|
|
stages: [lint]
|
|
|
|
shellcheck:
|
|
stage: lint
|
|
# The -alpine variant, not koalaman/shellcheck:stable. That one is built
|
|
# FROM scratch with shellcheck as the entrypoint and no shell at all, so the
|
|
# runner cannot start a job script in it and the job dies before it runs
|
|
# ("OCI runtime create failed"). Clearing the entrypoint does not help: there
|
|
# is still no /bin/sh to clear it to.
|
|
image: koalaman/shellcheck-alpine:stable@sha256:c82fe42504fbc9fc68f15d36638e5ee2324ebb8b94e96a3c4e395bf361c49183 # stable
|
|
script:
|
|
- |
|
|
files=$(find . -name '*.sh' -not -path './.git/*' | sort)
|
|
[ -n "$files" ] || { echo "no shell scripts found"; exit 1; }
|
|
echo "$files" | tr '\n' ' '
|
|
shellcheck --severity=warning --format=gcc $files
|
|
rules:
|
|
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
|
|
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
|