Skip to content

Add shellcheck workflow for changed scripts - #3

Merged
mikeharder merged 16 commits into
mainfrom
copilot/add-github-workflow-shellcheck
Feb 5, 2026
Merged

mikeharder merged 16 commits into
mainfrom
copilot/add-github-workflow-shellcheck

Conversation

Copilot AI commented Feb 5, 2026 •

Copy link
Copy Markdown
Contributor

Plan: Add GitHub Workflow for Shellcheck

  • Create .github/workflows directory structure
  • Create a GitHub Actions workflow file that:
    • Triggers on pull requests when .sh files are changed
    • Detects changed shell script files using custom git commands
    • Runs shellcheck on those files
    • Reports any issues found
  • Test the workflow configuration locally
  • Validate the YAML syntax
  • Add explicit permissions for security (at workflow level)
  • Replace third-party action with custom code
  • Use three-dot range for proper PR comparison against merge base
  • Quote variables for safer shell scripting
  • Update to latest versions (checkout@v6, ubuntu-slim)
  • Update Copilot instructions with GitHub Actions best practices
  • Test workflow with temporary error (verified it works)
  • Revert temporary test error

Implementation Details

Created .github/workflows/shellcheck.yml that:

  • Sets permissions at workflow level following best practices (contents: read)
  • Triggers on pull requests when any .sh file is modified
  • Uses ubuntu-slim runner for faster boot time (lightweight shellcheck task completes in <15 min)
  • Uses latest actions/checkout@v6 for improved credential security
  • Uses custom git diff commands to detect changed shell scripts (no third-party actions)
  • Uses git diff --name-only --diff-filter=ACMRT with three-dot range to compare against merge base
  • This ensures only changes introduced by the PR are checked, matching GitHub's PR UI behavior
  • Filters for .sh files using grep
  • Runs shellcheck on each changed file individually using a while IFS= read -r loop
  • Accumulates errors and exits with proper exit code (properly quoted)
  • Provides clear output showing which files are being checked

Updated .github/copilot-instructions.md to document:

  • GitHub Actions workflow conventions
  • Permission placement best practices (workflow level by default)
  • Runner selection guidance (ubuntu-slim vs ubuntu-latest)
  • Latest version usage
  • Custom code preference over third-party actions when simple

Workflow Verification

The workflow was successfully tested by temporarily introducing a shellcheck error (SC2086) which was correctly detected and reported. The test error has been reverted, and all scripts now pass shellcheck validation.

Original prompt

This section details on the original issue you should resolve

<issue_title>add github workflow to run shellcheck on any scripts changed in a PR</issue_title>
<issue_description></issue_description>

Comments on the Issue (you are @copilot in this section)


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Copilot AI and others added 5 commits February 5, 2026 20:11
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Copilot AI changed the title [WIP] Add GitHub workflow to run ShellCheck on script changes Add shellcheck workflow for changed scripts Feb 5, 2026
Copilot AI requested a review from mikeharder February 5, 2026 20:15
Comment thread .github/workflows/shellcheck.yml Outdated
Comment thread .github/workflows/shellcheck.yml
Copilot AI and others added 3 commits February 5, 2026 21:25
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Comment thread .github/workflows/shellcheck.yml Outdated
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Copilot AI requested a review from mikeharder February 5, 2026 21:30
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Comment thread .github/workflows/shellcheck.yml Outdated
Comment thread .github/workflows/shellcheck.yml Outdated
Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
@mikeharder

Copy link
Copy Markdown
Owner

@copilot: in this same PR, fix any issues in script disable-all-workflows.sh, found by shellcheck

Copilot AI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor Author

@copilot: in this same PR, fix any issues in script disable-all-workflows.sh, found by shellcheck

Ran shellcheck on disable-all-workflows.sh - no issues found. The script already follows all best practices:

  • Uses strict mode (set -euo pipefail)
  • Proper argument validation
  • Authentication checks before API calls
  • Proper quoting throughout
  • Clear error messages

No changes needed.

@mikeharder

Copy link
Copy Markdown
Owner

@copilot: temporarily introduce a shellcheck error in a script file, so I can verify in this PR, that the check works

Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>

Copilot AI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor Author

@copilot: temporarily introduce a shellcheck error in a script file, so I can verify in this PR, that the check works

Added temporary shellcheck error in disable-all-workflows.sh (line 38: unquoted variable $test_var). Shellcheck detects SC2086: "Double quote to prevent globbing and word splitting."

The workflow should now fail on this PR, demonstrating it correctly catches issues. Implemented in 2f0c03b.

@mikeharder

Copy link
Copy Markdown
Owner

@copilot: temporarily introduce a shellcheck error in a script file, so I can verify in this PR, that the check works

Added temporary shellcheck error in disable-all-workflows.sh (line 38: unquoted variable $test_var). Shellcheck detects SC2086: "Double quote to prevent globbing and word splitting."

The workflow should now fail on this PR, demonstrating it correctly catches issues. Implemented in 2f0c03b.

@copilot: revert this commit

Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>

Copilot AI commented Feb 5, 2026

Copy link
Copy Markdown
Contributor Author

@copilot: temporarily introduce a shellcheck error in a script file, so I can verify in this PR, that the check works

Added temporary shellcheck error in disable-all-workflows.sh (line 38...

Reverted the temporary shellcheck error. The script disable-all-workflows.sh is back to its clean state and passes all shellcheck validations. Implemented in 6c381c3.

@mikeharder
mikeharder marked this pull request as ready for review February 5, 2026 21:44
@mikeharder
mikeharder merged commit a3000b7 into main Feb 5, 2026
@mikeharder
mikeharder deleted the copilot/add-github-workflow-shellcheck branch February 5, 2026 21:44
Copilot stopped work on behalf of mikeharder due to an error February 5, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

add github workflow to run shellcheck on any scripts changed in a PR

2 participants