Repository navigation
69 lines (59 loc) · 2.71 KB
/
Copy pathvalidate.yml
File metadata and controls
69 lines (59 loc) · 2.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
name: Validate ShellKnight
# Syntax gate for fleet safety: Datto RMM pulls ShellKnight.ps1 straight from
# this repo, so a parse error on main ships to every endpoint. This workflow
# blocks that failure mode - it parses the script and runs PSScriptAnalyzer
# on every push/PR that touches a .ps1 file.
on:
push:
paths: ['**.ps1', '.github/workflows/validate.yml']
pull_request:
paths: ['**.ps1', '.github/workflows/validate.yml']
workflow_dispatch:
# Note: this workflow is the only gate between an edit and every managed
# endpoint, because the fleet pulls ShellKnight.ps1 from raw main on each run.
# Validate on a branch before merging.
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Parse check (blocks merge on syntax errors)
shell: pwsh
run: |
$tokens = $null; $errors = $null
[void][System.Management.Automation.Language.Parser]::ParseFile(
"$PWD/ShellKnight.ps1", [ref]$tokens, [ref]$errors)
if ($errors.Count -gt 0) {
foreach ($e in $errors) {
Write-Host "::error file=ShellKnight.ps1,line=$($e.Extent.StartLineNumber)::$($e.Message)"
}
throw "Parse FAILED: $($errors.Count) syntax error(s)"
}
Write-Host "Parse OK - ShellKnight.ps1 has no syntax errors"
- name: Unit tests (pure helpers, no Windows needed)
shell: pwsh
run: |
$failed = 0
Get-ChildItem ./tests -Filter 'Test-*.ps1' -ErrorAction SilentlyContinue | ForEach-Object {
Write-Host "::group::$($_.Name)"
& $_.FullName
if ($LASTEXITCODE -ne 0) { $failed++ }
Write-Host "::endgroup::"
}
if ($failed -gt 0) { throw "$failed test script(s) failed" }
- name: PSScriptAnalyzer (errors block, warnings inform)
shell: pwsh
run: |
Install-Module PSScriptAnalyzer -Force -Scope CurrentUser
$results = Invoke-ScriptAnalyzer -Path ./ShellKnight.ps1 -Severity Error,Warning
$warnings = @($results | Where-Object Severity -eq 'Warning')
$errors = @($results | Where-Object Severity -eq 'Error')
foreach ($w in $warnings) {
Write-Host "::warning file=ShellKnight.ps1,line=$($w.Line)::[$($w.RuleName)] $($w.Message)"
}
foreach ($e in $errors) {
Write-Host "::error file=ShellKnight.ps1,line=$($e.Line)::[$($e.RuleName)] $($e.Message)"
}
Write-Host ""
Write-Host "PSScriptAnalyzer: $($errors.Count) error(s), $($warnings.Count) warning(s)"
if ($errors.Count -gt 0) { throw "PSScriptAnalyzer found $($errors.Count) error(s)" }