Skip to content

v0.1.0 - first release

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 17:55
· 24 commits to main since this release

First release.

  • Scans .github/workflows/*.yml and action.yml files for uses: references and reads the real runs.using of the pinned ref through the GitHub API (cached, concurrency-limited, retries on 5xx).
  • Looks through composite actions and reusable workflows (depth 4, cycle-safe).
  • Rules: action-runtime-deprecated, action-runtime-nested, action-runtime-unresolved, local-action-runtime.
  • Suggests the smallest newer major whose release declares a supported runtime, with the commit SHA for pinning.
  • --fix rewrites tag refs and SHA pins (adding the version as a comment); CRLF files are preserved.
  • Output: text, markdown, json, GitHub annotations, SARIF 2.1.0 (validated against the official schema in tests).
  • Composite GitHub Action with a committed bundle (no nested actions, no setup-node), Marketplace metadata.

See the README for real output, rules, limitations and how it compares to existing tools.

Marketplace: the action metadata (name, description <=125 chars, branding) is ready; publishing to the Marketplace is a manual step by the owner.