name: placeholder-check description: Fail the build when placeholder images (via.placeholder.com, placehold.co, picsum.photos, ...) would ship. author: placeholder.com branding: icon: image color: gray-dark inputs: path: description: Files or directories to scan, separated by spaces or newlines (usually your build output). required: false default: dist args: description: Extra options, e.g. "--allow picsum.photos/seed/ --ignore 'docs/**' --exit-zero". required: false default: "" outputs: exit-code: description: 0 = clean, 1 = placeholders found, 2 = usage or read error. value: ${{ steps.check.outputs.exit-code }} runs: using: composite steps: - id: check shell: bash env: PH_PATHS: ${{ inputs.path }} PH_ARGS: ${{ inputs.args }} run: | set -f # no glob expansion: paths and patterns reach the script as written # Inputs come in through env and are split with shlex, never interpolated into this script. quoted=$(printf '%s' "$PH_ARGS" | python3 -c 'import shlex, sys; print(" ".join(map(shlex.quote, shlex.split(sys.stdin.read()))))') \ || { echo "::error title=placeholder-check::could not parse the args input"; echo "exit-code=2" >> "$GITHUB_OUTPUT"; exit 2; } eval "set -- $quoted" paths=($PH_PATHS) code=0 python3 "$GITHUB_ACTION_PATH/placeholder-check" "$@" -- "${paths[@]}" || code=$? echo "exit-code=$code" >> "$GITHUB_OUTPUT" exit "$code"