Repository navigation
v0.1.0 - first release
First release.
- Scans
.github/workflows/*.ymlandaction.ymlfiles foruses:references and reads the realruns.usingof the pinned ref through the GitHub API (cached, concurrency-limited, retries on 5xx). - Looks through composite actions and reusable workflows (depth 4, cycle-safe).
- Rules:
action-runtime-deprecated,action-runtime-nested,action-runtime-unresolved,local-action-runtime. - Suggests the smallest newer major whose release declares a supported runtime, with the commit SHA for pinning.
--fixrewrites tag refs and SHA pins (adding the version as a comment); CRLF files are preserved.- Output: text, markdown, json, GitHub annotations, SARIF 2.1.0 (validated against the official schema in tests).
- Composite GitHub Action with a committed bundle (no nested actions, no setup-node), Marketplace metadata.
See the README for real output, rules, limitations and how it compares to existing tools.
Marketplace: the action metadata (name, description <=125 chars, branding) is ready; publishing to the Marketplace is a manual step by the owner.