github / github/vscode-github-actions

Feature: warn when workflow YAML validates but would fail at runtime (schema vs runner gap)

Đang mở
#611 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
TypeScript
Star
660
Fork
213
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

### Summary

Extension validates workflow YAML against the schema, but many mistakes only surface after `git push` triggers a runner:

- `runs-on:` referencing a self-hosted label that has no online runner
- `uses: owner/repo@ref` where `ref` no longer resolves (deleted tag/branch, moved SHA)
- `secrets: inherit` on a reusable workflow whose caller does not actually inherit
- `permissions:` narrower than what a step needs (e.g. `contents: read` + a step that pushes)
- `if:` expression referencing a context that is empty for the trigger (e.g. `github.event.pull_request.*` on `push`)

Each case validates green locally, then burns a runner minute and a red X on the PR.

### Proposal

A "runtime-plausibility" pass, opt-in (`github-actions.runtimeChecks.enabled`), that runs alongside schema validation and surfaces `Information`-level diagnostics for:

1. Unresolvable `uses:` refs (HEAD probe via the authenticated session already used for the API tree)
2. `runs-on:` labels not present in the repo's runner list
3. `permissions:` narrower than the union of permissions declared by any resolvable action's `action.yml`
4. Context references that are empty for the declared `on:` triggers

None block save; all are dismissible. Runs on open + on save, cached by workflow-file hash.

### Why not `act` / nektos

`act` runs the whole workflow in Docker; this is a static, seconds-scale lint. Complementary, not overlapping.

### Related

- #593 (commit-pinned actions reported unresolved) - same "static analysis of `uses:`" surface
- #609 (false-positive missing-required-inputs) - related schema-vs-runtime gap in the other direction

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by tracing the existing workflow YAML schema-validation entry point and the authenticated session already used for the API tree. Review how action.yml files and workflow triggers are resolved, then determine how the four opt-in runtime checks and workflow-file-hash cache fit alongside validation. Done means dismissible Information diagnostics run on open and save without blocking saves.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
github-actions, typescript
Lĩnh vực
ci-cd, devtools
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.