Skip to content

Adopt central lint workflows for infra and repository docs #37

Description

@DevOpsDerek

Evidence

The repo already enforces .NET format/build/tests, Terraform linting, Markdown linting, filesystem security scanning, and the central Actions/gh-aw validator. Terraform checks currently target only infra/, while infra/bootstrap is a separate root. The four gh-aw Markdown source files are excluded from markdownlint; actionlint already covers authored workflow YAML. Dockerfile lint is absent, and Trivy config scanning does not currently show an enforcing exit code.

Scope

Adopt centrally published reusable lint workflows only for confirmed gaps: include infra/bootstrap in Terraform lint/validate, lint gh-aw Markdown authoring sources without generated locks, and evaluate central Hadolint for src/Api/Dockerfile. Preserve existing .NET, filesystem, and central action validation. Make a separately documented decision for Trivy config failure policy; do not silently make unrelated CI changes.

Acceptance criteria

  • Use central workflow calls pinned to immutable full SHAs, read-only permissions, and pinned tool versions.
  • Validate both Terraform roots with their existing config and preserve existing plan/credential boundaries.
  • Scope Markdown lint to authored sources, not lock files; no duplicate actionlint.
  • Add Dockerfile lint only if central tool supports the exact file and checks are green.
  • Keep all existing build/test/security gates intact and pass CI.

Blocked on DevOpsDerek/workflows#5; leave unassigned in Project #2 Backlog until implementation begins.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions