From 0551c633a3589861e05c11e54e582f56e9b36a99 Mon Sep 17 00:00:00 2001 From: Constantin Graf Date: Tue, 22 Sep 2026 12:35:47 +0200 Subject: [PATCH] Add github action to prevent non-tag refs in manifest.json --- .../workflows/extension-manifest-check.yml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 .github/workflows/extension-manifest-check.yml diff --git a/.github/workflows/extension-manifest-check.yml b/.github/workflows/extension-manifest-check.yml new file mode 100644 index 00000000..027c5970 --- /dev/null +++ b/.github/workflows/extension-manifest-check.yml @@ -0,0 +1,31 @@ +name: Extension Manifest Check +on: + pull_request: + paths: + - extensions/manifest.json + - .github/workflows/extension-manifest-check.yml +permissions: + contents: read +jobs: + check-refs: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: "Checkout code" + uses: actions/checkout@v7 + + # Extension refs must be pinned to a release tag (vX.Y.Z) or a full commit + # SHA. Branch names (main, feature/foo, ...) are only acceptable while + # developing and must be replaced before the pull request is merged. + - name: "Check extension refs are pinned" + run: | + failed=0 + while IFS=$'\t' read -r name ref; do + if [[ "$ref" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([-+][0-9A-Za-z.]+)?$ ]] || [[ "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "✅ $name: $ref" + else + echo "::error file=extensions/manifest.json::Extension \"$name\" uses ref \"$ref\", which is not a release tag or commit SHA. Pin it before merging." + failed=1 + fi + done < <(jq -r 'to_entries[] | [.key, .value.ref] | @tsv' extensions/manifest.json) + exit $failed