GitHub Actions Reference Pin and Archived-Action Inventory avatar

GitHub Actions Reference Pin and Archived-Action Inventory

Pricing

from $20.00 / 1,000 repository auditeds

Go to Apify Store
GitHub Actions Reference Pin and Archived-Action Inventory

GitHub Actions Reference Pin and Archived-Action Inventory

Reads the workflow files of a public repository set and reports every `uses:` reference: mutable tag or branch against commit sha pin, archived, renamed or missing action repositories, the last release date and a risk class. One dataset row for each refer

Pricing

from $20.00 / 1,000 repository auditeds

Rating

0.0

(0)

Developer

kingii98

kingii98

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

13 days ago

Last modified

Categories

Share

Give one table of every uses: reference in a set of public GitHub repositories. The table shows which references are mutable tags or branches, which point to an archived, renamed or missing Action, when the Action was last released, and whether the owner account changed.

Use it before a security review, before a customer questionnaire, or as a weekly CI hygiene run.

The Actor sends HTTP GET calls to the public GitHub REST API and reads the workflow bodies from raw.githubusercontent.com. There is no browser, no proxy, no database, and no write call. A token is optional.

What the Actor does

  1. It lists .github/workflows of each repository.
  2. It reads each workflow file and finds every uses: value, with its job and its step index.
  3. It reads each distinct Action repository once: the archive flag, the owner account and its type, the default branch, the last release and the last push.
  4. It resolves the commit sha of each mutable reference, up to the configured bound.
  5. It applies two rules and writes one row for each reference.

The pin rule

A reference passes the pin rule when it names a full 40 character commit sha. A tag, a branch, a short sha and a uses: value without @ all fail the rule, because the code behind them can change. A container image passes when it carries a @sha256: digest.

An owner in trustedOwners is free of the pin rule. It is not free of the maintenance rule.

A local reference (./.github/actions/...) is reported and never flagged: it lives in the audited repository itself.

The maintenance rule

A reference passes the maintenance rule when the Action repository is active, and when it had a release or a push inside staleReleaseDays. An archived, a renamed and a missing Action repository all fail the rule.

An Action repository that the Actor could not read (for example because of the GitHub rate limit) gets the state unknown. It is reported, but it is not flagged and it is not charged.

Reference type

GitHub does not say in the reference itself whether a name is a tag or a branch. The Actor reads the name the way a reviewer reads it: a full or short hexadecimal name is a sha, a version name such as v4 or 1.2.3 is a tag, the default branch of the Action and the common branch names are a branch, and every other name is a branch. A tag and a branch are both mutable, so this reading does not change the verdict.

Input

All fields have a default, so a run with an empty input {} works.

FieldMeaning
repositories1 to 200 public repositories as owner/repo. A GitHub URL is also accepted.
branchBranch, tag or commit to read the workflow files from. Empty means the default branch.
trustedOwnersOwner accounts that may use a mutable reference, for example actions.
staleReleaseDaysAn Action without a release or a push inside this many days fails the maintenance rule. Default 365.
maxWorkflowFilesPerRepoHighest number of workflow files read in one repository, in name order. Default 3.
resolveCommitShaSend one extra call for each mutable reference to resolve the commit sha it points to today.
maxShaResolutionsUpper bound on those extra calls. Default 5.
maxReferencesUpper bound on the reference rows of one run. Default 2000.
onlyFlaggedWrite a row only for a flagged reference. The summary always counts every reference.
githubTokenOptional read-only token. Anonymous callers may send 60 API calls in one hour.
concurrencyRepositories audited at the same time. Default 4.
requestsPerSecondUpper bound on the call rate. Default 5.
timeoutSecondsTimeout of one call. Default 15.
maxResponseBytesAn answer above this size is refused and becomes a reported failure.

Example:

{
"repositories": ["actions/checkout", "peter-evans/create-pull-request"],
"trustedOwners": ["actions"],
"staleReleaseDays": 365
}

Output

One dataset row for each reference, plus one summary record.

FieldMeaning
repositoryThe audited repository.
workflowFileThe workflow file name, for example ci.yml.
workflowPathThe full path of the workflow file.
jobIdThe job key in the workflow file.
jobNameThe name: of the job, when it has one.
stepIndexThe position of the step inside the job, counted from 0.
stepNameThe name: of the step, when it has one.
actionReferenceThe uses: value as written.
actionRepoThe Action repository, or null for a local or container reference.
referenceTypesha, tag, branch, local, docker or none.
resolvedCommitShaThe commit sha the reference points to today.
actionRepoStateactive, archived, renamed, missing or unknown.
resolvedActionRepoThe current name of the Action repository after a rename.
actionOwnerThe owner account of the Action.
actionOwnerTypeOrganization or User.
ownerTypeChangeFlagTrue when the Action moved to another owner account.
lastReleaseAtThe date of the last release of the Action.
lastActivityAtThe later of the last release and the last push.
daysSinceReleaseDays since the last release.
daysSinceActivityDays since the last release or push.
trustedOwnerTrue when the owner is in trustedOwners.
pinRulePassThe verdict of the pin rule.
maintenanceRulePassThe verdict of the maintenance rule.
flaggedTrue when one of the two rules fails. This is the charged finding.
riskClassThe highest risk of the row, see below.
riskReasonsEvery risk name that applies to the row.
noteThe reason why an Action could not be read.
statusSummary record: CLEAN, FLAGS_FOUND or NO_REPOSITORY_READ.
checkedAtThe start time of the run.

Risk classes, from high to low: missing-action, archived-action, renamed-action, unmaintained-action, unreadable-reference, unpinned-container-image, unpinned-branch, mutable-tag, short-sha-pin, unverified-action, local-action, pinned-and-maintained.

The summary record also carries repositoriesRequested, repositoriesAudited, repositoriesFailed, workflowFilesRead, referencesFound, referencesFlagged, byRiskClass, failures, shaResolutions, requestsSent, truncated and rateLimited.

Charged events

The Actor is paid for each event:

EventUnitPrice
repository-auditedOne public repository whose workflow files were read. A repository that could not be read is reported, not charged.USD 0.02
action-reference-flaggedOne reference that fails the pin rule or the maintenance rule. An Action with the state unknown is not charged.USD 0.004

A clean repository therefore costs one event only. The finding event makes the charge follow the delivered findings.

A verdict is not a failure

A failed gate is a result, not a malfunction. Zero findings, a missing repository, a repository without workflow files, and a run that the GitHub rate limit cut short all end with a SUCCEEDED run, a dataset record and a status message. A FAILED run means that the Actor itself broke, or that the input could not be parsed.

Limits

  • Public repositories only. A private repository answers 404 and is reported.
  • Anonymous callers may send 60 GitHub API calls in one hour. Supply githubToken for a run over more than a few repositories.
  • The Actor reads maxWorkflowFilesPerRepo files for each repository, in name order. Raise it for a complete audit.
  • A tag and a branch are told apart by their name, see above.

Development

uv sync
uv run pytest
uv run ruff check .