It performs differential ShellCheck scans and report results directly in pull request.
documentation: https://github.com/redhat-plumbers-in-action/differential-shellcheck
Signed-off-by: Jan Macku <jamacku@redhat.com>
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
+
+ differential-shellcheck:
+ if: github.event_name == 'pull_request'
+ runs-on: ubuntu-latest
+
+ permissions:
+ contents: read
+ security-events: write
+ pull-requests: write
+
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v3
+ with:
+ fetch-depth: 0
+
+ # Doc: https://github.com/redhat-plumbers-in-action/differential-shellcheck#usage
+ - name: Differential ShellCheck
+ uses: redhat-plumbers-in-action/differential-shellcheck@v3
+ with:
+ severity: warning
+ token: ${{ secrets.GITHUB_TOKEN }}