yaml_path_absent
Assert a JSONPath query over the document matches nothing; one file-level violation if present.
Semantics:
- The query must select zero nodes. Any match fires exactly one violation for the file — never per-match, so a
$[?…]filter that fans out over every top-level key still yields a single violation. - The existence sibling of the value-checking kinds; mirrors
file_absentfor a path.equals/matches/if_presentdon’t apply. - Useful for forbidding a key: a
postinstallscript inpackage.json, a[patch]table inCargo.toml, orwrite-allpermissions in a workflow.
Options
Section titled “Options”| Option | Type | Required | Default | Description |
|---|---|---|---|---|
path | string | yes | JSONPath expression rooted at $. The rule fires one violation per file if the query matches any node (the path must be absent). |
Plus the common paths, level, id, and when fields. This table is generated from the JSON Schema; option types and defaults are authoritative.
Example
Section titled “Example”A workflow that grants write-all to the GITHUB_TOKEN
Section titled “A workflow that grants write-all to the GITHUB_TOKEN”The rule fires on this repository:
.github/.github/workflows/.github/workflows/ci.ymlname: CIon: pushpermissions: write-alljobs: build: runs-on: ubuntu-latest steps: - run: echo hiWith this .alint.yml:
version: 1rules: - id: no-write-all-token kind: yaml_path_absent paths: ".github/workflows/*.yml" path: "$[?($.permissions == 'write-all')]" level: error message: >- Workflow grants `write-all` to the GITHUB_TOKEN; restrict it to `contents: read` (or narrower).alint check reports:
--- .github/workflows/ci.yml --------------------------------------------------- x error no-write-all-token Workflow grants `write-all` to the GITHUB_TOKEN; restrict it to `contents: read` (or narrower).
Summary (1 violation): x 1 error 0 passing * 1 failingA workflow that restricts the token to read
Section titled “A workflow that restricts the token to read”This repository is compliant:
.github/.github/workflows/.github/workflows/ci.ymlname: CIon: pushpermissions: contents: readjobs: build: runs-on: ubuntu-latest steps: - run: echo hiWith this .alint.yml:
version: 1rules: - id: no-write-all-token kind: yaml_path_absent paths: ".github/workflows/*.yml" path: "$[?($.permissions == 'write-all')]" level: error message: >- Workflow grants `write-all` to the GITHUB_TOKEN; restrict it to `contents: read` (or narrower).alint check reports:
v All 1 rule(s) passed.