Skip to main content

githubActions.configs.all

Enables the complete bundled rule set published by eslint-plugin-github-actions-2, while leaving explicitly opt-in policy rules manual.

Included rulesโ€‹

Fix legend:

  • ๐Ÿ”ง = autofixable
  • ๐Ÿ’ก = suggestions available
  • โ€” = report only
RuleFix
R009 action-name-casing๐Ÿ”ง
R010 job-id-casingโ€”
R011 max-jobs-per-actionโ€”
R048 no-case-insensitive-input-id-collisionโ€”
R097 no-codeql-autobuild-for-javascript-typescriptโ€”
R096 no-codeql-javascript-typescript-split-language-matrixโ€”
R049 no-composite-input-env-accessโ€”
R044 no-deprecated-node-runtimeโ€”
R051 no-duplicate-composite-step-idโ€”
R060 no-empty-template-file-pattern๐Ÿ”ง
R012 no-external-jobโ€”
R068 no-hardcoded-default-branch-in-templateโ€”
R063 no-icon-file-extension-in-template-icon-name๐Ÿ”ง
R026 no-inherit-secretsโ€”
R042 no-invalid-concurrency-contextโ€”
R019 no-invalid-keyโ€”
R041 no-invalid-reusable-workflow-job-keyโ€”
R059 no-invalid-template-file-pattern-regexโ€”
R040 no-invalid-workflow-call-output-valueโ€”
R095 no-overlapping-dependabot-directoriesโ€”
R064 no-path-separators-in-template-icon-name๐Ÿ’ก
R046 no-post-if-without-post๐Ÿ”ง
R030 no-pr-head-checkout-in-pull-request-targetโ€”
R045 no-pre-if-without-pre๐Ÿ”ง
R047 no-required-input-with-default๐Ÿ’ก
R027 no-secrets-in-ifโ€”
R036 no-self-hosted-runner-on-fork-pr-eventsโ€”
R062 no-subdirectory-template-file-patternโ€”
R069 no-template-placeholder-in-non-template-workflowโ€”
R013 no-top-level-envโ€”
R061 no-universal-template-file-patternโ€”
R081 no-unknown-dependabot-multi-ecosystem-groupโ€”
R050 no-unknown-input-reference-in-compositeโ€”
R037 no-unknown-job-output-referenceโ€”
R038 no-unknown-step-referenceโ€”
R029 no-untrusted-input-in-runโ€”
R085 no-unused-dependabot-enable-beta-ecosystems๐Ÿ”ง
R053 no-unused-input-in-compositeโ€”
R023 no-write-all-permissionsโ€”
R003 pin-action-shasโ€”
R043 prefer-action-ymlโ€”
R015 prefer-fail-fastโ€”
R020 prefer-file-extensionโ€”
R033 prefer-inputs-context๐Ÿ”ง
R016 prefer-step-uses-styleโ€”
R066 prefer-template-yml-extensionโ€”
R005 require-action-nameโ€”
R006 require-action-run-nameโ€”
R025 require-checkout-before-local-actionโ€”
R099 require-codeql-actions-readโ€”
R113 require-codeql-branch-filtersโ€”
R114 require-codeql-category-when-language-matrixโ€”
R100 require-codeql-pull-request-triggerโ€”
R101 require-codeql-scheduleโ€”
R098 require-codeql-security-events-writeโ€”
R052 require-composite-step-nameโ€”
R077 require-dependabot-assigneesโ€”
R111 require-dependabot-automation-permissionsโ€”
R112 require-dependabot-automation-pull-request-triggerโ€”
R109 require-dependabot-bot-actor-guardโ€”
R089 require-dependabot-commit-message-include-scopeโ€”
R079 require-dependabot-commit-message-prefixโ€”
R090 require-dependabot-commit-message-prefix-developmentโ€”
R086 require-dependabot-cooldownโ€”
R073 require-dependabot-directoryโ€”
R084 require-dependabot-github-actions-directory-root๐Ÿ”ง
R080 require-dependabot-labelsโ€”
R087 require-dependabot-open-pull-requests-limitโ€”
R072 require-dependabot-package-ecosystemโ€”
R082 require-dependabot-patterns-for-multi-ecosystem-groupโ€”
R083 require-dependabot-schedule-cronjobโ€”
R074 require-dependabot-schedule-intervalโ€”
R075 require-dependabot-schedule-timeโ€”
R076 require-dependabot-schedule-timezoneโ€”
R078 require-dependabot-target-branchโ€”
R071 require-dependabot-updatesโ€”
R070 require-dependabot-version๐Ÿ”ง
R088 require-dependabot-versioning-strategy-for-npmโ€”
R091 require-dependency-review-actionโ€”
R093 require-dependency-review-fail-on-severityโ€”
R092 require-dependency-review-permissions-contents-readโ€”
R094 require-dependency-review-pull-request-triggerโ€”
R110 require-fetch-metadata-github-tokenโ€”
R007 require-job-name๐Ÿ’ก
R008 require-job-step-name๐Ÿ’ก
R002 require-job-timeout-minutesโ€”
R035 require-merge-group-triggerโ€”
R032 require-pull-request-target-branchesโ€”
R021 require-run-step-shellโ€”
R102 require-sarif-upload-security-events-writeโ€”
R103 require-scorecard-results-format-sarifโ€”
R104 require-scorecard-upload-sarif-stepโ€”
R107 require-secret-scan-contents-readโ€”
R105 require-secret-scan-fetch-depth-zeroโ€”
R106 require-secret-scan-scheduleโ€”
R057 require-template-categoriesโ€”
R058 require-template-file-patternsโ€”
R065 require-template-icon-file-existsโ€”
R056 require-template-icon-nameโ€”
R067 require-template-workflow-nameโ€”
R031 require-trigger-typesโ€”
R108 require-trufflehog-verified-results-modeโ€”
R034 require-workflow-call-input-typeโ€”
R039 require-workflow-call-output-valueโ€”
R004 require-workflow-concurrencyโ€”
R022 require-workflow-dispatch-input-typeโ€”
R024 require-workflow-interface-descriptionโ€”
R001 require-workflow-permissionsโ€”
R028 require-workflow-run-branchesโ€”
R054 require-workflow-template-pairโ€”
R055 require-workflow-template-properties-pairโ€”
R017 valid-timeout-minutesโ€”
R018 valid-trigger-eventsโ€”