GitHub Actions Reference Pin and Archived-Action Inventory
Pricing
from $20.00 / 1,000 repository auditeds
GitHub Actions Reference Pin and Archived-Action Inventory
Reads the workflow files of a public repository set and reports every `uses:` reference: mutable tag or branch against commit sha pin, archived, renamed or missing action repositories, the last release date and a risk class. One dataset row for each refer
Pricing
from $20.00 / 1,000 repository auditeds
Rating
0.0
(0)
Developer
kingii98
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
13 days ago
Last modified
Categories
Share
Give one table of every uses: reference in a set of public GitHub
repositories. The table shows which references are mutable tags or branches,
which point to an archived, renamed or missing Action, when the Action was
last released, and whether the owner account changed.
Use it before a security review, before a customer questionnaire, or as a weekly CI hygiene run.
The Actor sends HTTP GET calls to the public GitHub REST API and reads the
workflow bodies from raw.githubusercontent.com. There is no browser, no
proxy, no database, and no write call. A token is optional.
What the Actor does
- It lists
.github/workflowsof each repository. - It reads each workflow file and finds every
uses:value, with its job and its step index. - It reads each distinct Action repository once: the archive flag, the owner account and its type, the default branch, the last release and the last push.
- It resolves the commit sha of each mutable reference, up to the configured bound.
- It applies two rules and writes one row for each reference.
The pin rule
A reference passes the pin rule when it names a full 40 character commit sha.
A tag, a branch, a short sha and a uses: value without @ all fail the rule,
because the code behind them can change. A container image passes when it
carries a @sha256: digest.
An owner in trustedOwners is free of the pin rule. It is not free of the
maintenance rule.
A local reference (./.github/actions/...) is reported and never flagged: it
lives in the audited repository itself.
The maintenance rule
A reference passes the maintenance rule when the Action repository is active,
and when it had a release or a push inside staleReleaseDays. An archived, a
renamed and a missing Action repository all fail the rule.
An Action repository that the Actor could not read (for example because of the
GitHub rate limit) gets the state unknown. It is reported, but it is not
flagged and it is not charged.
Reference type
GitHub does not say in the reference itself whether a name is a tag or a
branch. The Actor reads the name the way a reviewer reads it: a full or short
hexadecimal name is a sha, a version name such as v4 or 1.2.3 is a tag,
the default branch of the Action and the common branch names are a branch,
and every other name is a branch. A tag and a branch are both mutable, so
this reading does not change the verdict.
Input
All fields have a default, so a run with an empty input {} works.
| Field | Meaning |
|---|---|
repositories | 1 to 200 public repositories as owner/repo. A GitHub URL is also accepted. |
branch | Branch, tag or commit to read the workflow files from. Empty means the default branch. |
trustedOwners | Owner accounts that may use a mutable reference, for example actions. |
staleReleaseDays | An Action without a release or a push inside this many days fails the maintenance rule. Default 365. |
maxWorkflowFilesPerRepo | Highest number of workflow files read in one repository, in name order. Default 3. |
resolveCommitSha | Send one extra call for each mutable reference to resolve the commit sha it points to today. |
maxShaResolutions | Upper bound on those extra calls. Default 5. |
maxReferences | Upper bound on the reference rows of one run. Default 2000. |
onlyFlagged | Write a row only for a flagged reference. The summary always counts every reference. |
githubToken | Optional read-only token. Anonymous callers may send 60 API calls in one hour. |
concurrency | Repositories audited at the same time. Default 4. |
requestsPerSecond | Upper bound on the call rate. Default 5. |
timeoutSeconds | Timeout of one call. Default 15. |
maxResponseBytes | An answer above this size is refused and becomes a reported failure. |
Example:
{"repositories": ["actions/checkout", "peter-evans/create-pull-request"],"trustedOwners": ["actions"],"staleReleaseDays": 365}
Output
One dataset row for each reference, plus one summary record.
| Field | Meaning |
|---|---|
repository | The audited repository. |
workflowFile | The workflow file name, for example ci.yml. |
workflowPath | The full path of the workflow file. |
jobId | The job key in the workflow file. |
jobName | The name: of the job, when it has one. |
stepIndex | The position of the step inside the job, counted from 0. |
stepName | The name: of the step, when it has one. |
actionReference | The uses: value as written. |
actionRepo | The Action repository, or null for a local or container reference. |
referenceType | sha, tag, branch, local, docker or none. |
resolvedCommitSha | The commit sha the reference points to today. |
actionRepoState | active, archived, renamed, missing or unknown. |
resolvedActionRepo | The current name of the Action repository after a rename. |
actionOwner | The owner account of the Action. |
actionOwnerType | Organization or User. |
ownerTypeChangeFlag | True when the Action moved to another owner account. |
lastReleaseAt | The date of the last release of the Action. |
lastActivityAt | The later of the last release and the last push. |
daysSinceRelease | Days since the last release. |
daysSinceActivity | Days since the last release or push. |
trustedOwner | True when the owner is in trustedOwners. |
pinRulePass | The verdict of the pin rule. |
maintenanceRulePass | The verdict of the maintenance rule. |
flagged | True when one of the two rules fails. This is the charged finding. |
riskClass | The highest risk of the row, see below. |
riskReasons | Every risk name that applies to the row. |
note | The reason why an Action could not be read. |
status | Summary record: CLEAN, FLAGS_FOUND or NO_REPOSITORY_READ. |
checkedAt | The start time of the run. |
Risk classes, from high to low: missing-action, archived-action,
renamed-action, unmaintained-action, unreadable-reference,
unpinned-container-image, unpinned-branch, mutable-tag, short-sha-pin,
unverified-action, local-action, pinned-and-maintained.
The summary record also carries repositoriesRequested,
repositoriesAudited, repositoriesFailed, workflowFilesRead,
referencesFound, referencesFlagged, byRiskClass, failures,
shaResolutions, requestsSent, truncated and rateLimited.
Charged events
The Actor is paid for each event:
| Event | Unit | Price |
|---|---|---|
repository-audited | One public repository whose workflow files were read. A repository that could not be read is reported, not charged. | USD 0.02 |
action-reference-flagged | One reference that fails the pin rule or the maintenance rule. An Action with the state unknown is not charged. | USD 0.004 |
A clean repository therefore costs one event only. The finding event makes the charge follow the delivered findings.
A verdict is not a failure
A failed gate is a result, not a malfunction. Zero findings, a missing repository, a repository without workflow files, and a run that the GitHub rate limit cut short all end with a SUCCEEDED run, a dataset record and a status message. A FAILED run means that the Actor itself broke, or that the input could not be parsed.
Limits
- Public repositories only. A private repository answers 404 and is reported.
- Anonymous callers may send 60 GitHub API calls in one hour. Supply
githubTokenfor a run over more than a few repositories. - The Actor reads
maxWorkflowFilesPerRepofiles for each repository, in name order. Raise it for a complete audit. - A tag and a branch are told apart by their name, see above.
Development
uv syncuv run pytestuv run ruff check .