Skip to content

staging.yml template: declare sign-macos-packages input - #70297

Merged
dwoz merged 1 commit into
saltstack:masterfrom
dwoz:dwoz/sign-macos-input-declare-master
Sep 17, 2026
Merged

dwoz merged 1 commit into
saltstack:masterfrom
dwoz:dwoz/sign-macos-input-declare-master

Conversation

@dwoz

@dwoz dwoz commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Follow-up to the sign-macos-off-nightly change. That PR taught build-packages.yml.jinja to emit
sign-macos-packages: ${{ inputs.sign-macos-packages }} in non-nightly contexts, which means the RENDERED staging.yml now references an inputs.sign-macos-packages field that was never declared on staging.yml's own on: workflow_call: inputs: block.

actionlint on the Pre-Commit / Run Pre-Commit Against Salt job catches this and rejects staging.yml with:

property "sign-macos-packages" is not defined in object type
{sign-deb-packages: bool; sign-rpm-packages: bool;
 sign-windows-packages: bool; ...}

Local pre-commit runs did not surface this — likely because the local actionlint binary is a slightly older version, or the hook was skipped on the run. CI actionlint is stricter.

Fix: add sign-macos-packages: type=boolean, default=false to templates/staging.yml.jinja next to the other sign-* inputs. The regenerated staging.yml gets the new input declaration; the existing ${{ inputs.sign-macos-packages }} references at lines 518/541 now resolve correctly and actionlint stops complaining.

Regenerated .github/workflows/staging.yml via the Generate GitHub Workflow Templates pre-commit hook.

Follow-up to the sign-macos-off-nightly change. That PR taught
build-packages.yml.jinja to emit
`sign-macos-packages: ${{ inputs.sign-macos-packages }}` in
non-nightly contexts, which means the RENDERED staging.yml now
references an `inputs.sign-macos-packages` field that was never
declared on staging.yml's own `on: workflow_call: inputs:` block.

actionlint on the Pre-Commit / Run Pre-Commit Against Salt job
catches this and rejects staging.yml with:

    property "sign-macos-packages" is not defined in object type
    {sign-deb-packages: bool; sign-rpm-packages: bool;
     sign-windows-packages: bool; ...}

Local pre-commit runs did not surface this — likely because the
local actionlint binary is a slightly older version, or the hook
was skipped on the run. CI actionlint is stricter.

Fix: add sign-macos-packages: type=boolean, default=false to
templates/staging.yml.jinja next to the other sign-* inputs. The
regenerated staging.yml gets the new input declaration; the
existing `${{ inputs.sign-macos-packages }}` references at lines
518/541 now resolve correctly and actionlint stops complaining.

Regenerated .github/workflows/staging.yml via the Generate GitHub
Workflow Templates pre-commit hook.
@dwoz
dwoz requested a review from a team as a code owner September 17, 2026 08:26
@dwoz
dwoz merged commit 4c6b6a3 into saltstack:master Sep 17, 2026
3 checks passed

This branch was successfully deployed

1 active deployment
ci — 2b66b61b Deployed Sep 17, 2026 by dwoz via Build Onedir Packages / macOS (arm64) #27168
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant