Reusable GitHub Actions workflows forming the CI baseline for every BruzIT repository: semantic-release versioning and MegaLinter linting.
Reusable Semantic Release workflow using the Conventional Commits preset to automate versioning, tags with SemVer and major tag, generates GitHub releases, and updates the CHANGELOG.
Reusable MegaLinter workflow linting pull requests with the terraform flavor, auto-committing fixable findings. Linters run with MegaLinter's default rules, except zizmor, whose zizmor.yaml allows tag-pinned actions.
Create a workflow, for example, .github/workflows/semantic-release.yaml:
---
name: Semantic Release
on:
push:
branches:
- main
jobs:
release:
name: Release
uses: bruzit/github-actions-and-workflows/.github/workflows/semantic-release.yaml@v0
permissions:
contents: write
issues: write
pull-requests: write
with:
GH_SEM_REL_APP_ID: ${{ vars.GH_SEM_REL_APP_ID }}
semantic_release_plugins: "@semantic-release/exec" # OPTIONAL Space-separated list of additional semantic-release plugins to install.
secrets:
GH_SEM_REL_APP_PEM_FILE: ${{ secrets.GH_SEM_REL_APP_PEM_FILE }}To create a GitHub App and a GitHub App Installation:
- GitHub
- Organization / Settings / Developer settings / GitHub Apps
- New GitHub App
- Create GitHub App
- GitHub App name: name
- Description: description
- Homepage URL: homepage URL
- Webhook
- Active: off
- Permissions
- Organization permissions
- Contents: Read and write
- Issues: Read and write
- Pull requests: Read and write
- Where can this GitHub App be installed?: choose what suits you best
- Organization permissions
- Create GitHub App
- Create GitHub App
- your app
- General
- Generate a private key
- Install App
- your organization: Install
- General
- New GitHub App
- Repository / Settings / Secrets and variables / Actions
- Secrets
- Repository secrets / New repository secret
- Name:
GH_SEM_REL_APP_PEM_FILE - Secret: content of the PEM file
- Add secret
- Name:
- Repository secrets / New repository secret
- Variables
- Repository variables / New repository variable
- Name:
GH_SEM_REL_APP_ID - Value: GitHub App ID
- Add variable
- Name:
- Repository variables / New repository variable
- Secrets
- Organization / Settings / Developer settings / GitHub Apps
Configure Semantic Release in the repository, for example like this repository's .releaserc.yaml.
Create .github/workflows/megalinter.yaml:
---
name: MegaLinter
on:
pull_request:
jobs:
megalinter:
name: MegaLinter
uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
permissions:
contents: write
pull-requests: write
# with:
# validate_all_codebase: true # OPTIONAL Lint the whole repository, not only the changed files.Create .mega-linter.yml listing the linters for the repository, for example:
---
ENABLE:
- ACTION
- MARKDOWN
- YAMLAdd ANSIBLE, BASH or TERRAFORM to ENABLE as needed; ansible-lint additionally requires an .ansible-lint file. Copy zizmor.yaml into the repository root and add megalinter-reports/ to .gitignore.
Pull requests lint only changed files. To also lint the whole repository weekly, for example to catch newly published advisories for pinned action tags, create .github/workflows/megalinter-scheduled.yaml:
---
name: MegaLinter Scheduled
on:
schedule:
- cron: "0 6 * * 1"
workflow_dispatch:
jobs:
megalinter:
name: MegaLinter
uses: bruzit/github-actions-and-workflows/.github/workflows/megalinter.yaml@v0
permissions:
contents: write
pull-requests: write
with:
validate_all_codebase: trueFixes are not committed outside pull requests; findings fail the run.
This repository is linted by its own MegaLinter workflow. Run locally (needs Docker):
# report issues
docker run --rm -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10
# auto-fix where possible
docker run --rm -e APPLY_FIXES=all -v "$PWD":/tmp/lint oxsecurity/megalinter-terraform:v10MIT License
Copyright © 2026 Martin Bružina