forked from heavy-duty/box
CI's shellcheck sweep set globstar and globbed `bin/* **/*.sh`. globstar makes `**` descend into subdirectories, but a glob still does not MATCH a dot-prefixed name, so `**/` never entered `.github/` and three scripts were never linted: changelog-armed.sh (the #108/#110 guard that gates every PR), release-notes.sh (which produces the published release body), and labels-reconcile.sh (the label state machine). That is the entire release path, while the step's own comment promised the opposite — that a script in a new subdirectory is linted without anyone editing a list. Latent, not broken: all three pass shellcheck as-is, so this is a no-op on current code. What changes is that a regression in them would be caught. dotglob alongside globstar closes it, measured rather than assumed: it adds exactly those three and nothing else — a checkout's .git carries no *.sh, its hooks shipping as *.sample, so `**/*.sh` does not wander into it. The one-time fix is dotglob; what keeps the gap shut is the CLASS check, in the same shape as the eof_guard_sweep of #112. The sweep now compares the globbed set against `git ls-files '*.sh'` and fails naming any tracked script it does not cover, so a future dot-directory or shopt subtlety cannot silently lint a subset and pass. eof_guard_sweep carried the identical blind spot — it rebuilds the same glob — and is widened the same way. A no-op today: the three scripts set errexit, so they are in that class by construction, but none of them reads. Refs #116 |
||
|---|---|---|
| .. | ||
| ci.yml | ||
| labels.yml | ||
| release.yml | ||