github jdx/jactionlint v2.0.0

latest releases: v2.0.2, v2.0.1
4 hours ago

No binaries are attached to this release. Its build failed on a Ruby gem, and a tag cannot be moved once the Go checksum database has seen it. The first release with binaries is v2.0.1, which has the same code. These are the release notes of 2.0.0.

2.0.0 (2026-10-09)

⚠ BREAKING CHANGES

  • use POSIX/GNU command line options only (#85)
  • add the correctness, default and pedantic profiles and consolidate rule IDs (#79)
  • add stable rule IDs, severities, profiles and native output formats (v2) (#47)

Features

  • add a GitHub Action that downloads and runs jactionlint (v2) (#108) (b27de1f)
  • add a shared uses parser and keep yaml comments (#50) (da20b77)
  • add an internal analyzer for run scripts (#53) (be4bf70)
  • add baseline adoption with -baseline-write and -format summary (#75) (66bfa78)
  • add durable config ignores with expiry (#74) (4e72865)
  • add fixers for missing-timeout, missing-permissions and unused-ignore (#59) (17e1e45)
  • add stable rule IDs, severities, profiles and native output formats (v2) (#47) (0c06391)
  • add the concurrency, gate-job, untrusted-checkout and dead-code rules (#64) (6664fa4)
  • add the correctness, default and pedantic profiles and consolidate rule IDs (#79) (e42a7b9)
  • add the dependabot-cooldown and dependabot-execution rules (#63) (729babe)
  • add the excessive-permissions, unpinned-images, artipacked, cache-poisoning and other permission and pinning rules (#57) (00c2c1f)
  • add the github-env, adhoc-packages, unpinned-tools, use-trusted-publishing, superfluous-actions and unlocked-install rules (#62) (21c4e0c)
  • add the impostor-commit, known-vulnerable-actions, ref-confusion, stale-action-refs, archived-uses and ref-version-mismatch online rules (#60) (714ba46)
  • add the insecure-commands, unsound-contains, secrets-inherit, dangerous-triggers and other secrets and workflow-structure rules (#56) (be87194)
  • add the invisible-characters and unsound-prefix-match rules (#71) (4d6cb5e)
  • add the pipeline-without-pipefail rule (#65) (c373d0e)
  • add the template-injection tiers, bot-conditions, obfuscation and misfeature rules (#58) (70e11b9)
  • add the unverified-download, insecure-ssh-keyscan, checkout-static-credentials and insecure-url-scheme rules (#70) (eae08cc)
  • converge -fix, add -fix -rules and -diff, verify every pass (#76) (8944339)
  • extend template-injection to container and AI-agent sinks and add agentic-actions (#69) (6938d15)
  • honor zizmor ignore comments and add -migrate-ignores (#66) (23a3140)
  • lint composite action.yml files with caller-aware context (#72) (a0f2843)
  • lint dependabot.yml and add a visitor for dependabot rules (#51) (2f687b6)
  • make -online resilient to failed lookups and add token discovery (#73) (507b083)
  • use POSIX/GNU command line options only (#85) (baac11d)

Bug Fixes

  • apply zizmor ignores like zizmor, show rule IDs, lint every action, skip policy rules in generated files (#91) (d644def)
  • close the gaps in untrusted-artifact, agentic-actions and five more rules (#95) (fdf32d3)
  • cut false positives in the concurrency, gate, permissions and cooldown rules (#86) (ac69a21)
  • keep the baseline from hiding new missing inputs and validate the fix options (#98) (896cf35)
  • lint only direct workflow files, guide first runs, and dogfood the default profile (#84) (468ead1)
  • make large workflows fast, report exact positions in multi-line scalars and harden against pathological input (#83) (be058ab)
  • release: expand the signing identity in the codesign hook (#77) (885293f)
  • remove false positives and close coverage gaps found by the bug bash (#82) (7ed5ce1)
  • remove the false positives and false negatives of 14 rules found in round 2 (#89) (62c0fc0)
  • report positions inside YAML scalars exactly (#88) (7f6d89c)
  • share the online cache between tokens, honor online false and match config ignores (#97) (2c49f4b)
  • stop --fix from breaking reusable workflows and word lists, and make --diff minimal (#87) (6748c2f)
  • use the exact env name in the template-injection fix and tighten the cache-poisoning gates (#96) (7684ba2)

This PR was generated with Release Please. See documentation.

Don't miss a new jactionlint release

NewReleases is sending notifications on new releases.