Skip to content

GitHub Action v1.0.1

Choose a tag to compare

@fxjim fxjim released this 23 Jul 23:29
· 22 commits to main since this release

GitHub Action v1.0.1

Agent Commerce Guard provides a free policy-preflight Action and gives every completed run a direct path to the private local package and paid workflow API.

Use The Stable Major Ref

- uses: fxjim/agent-commerce-guard@v1
  with:
    manifest: agent-actions.json
    fail-on: blocked

The Action:

  • Reviews AI-agent wallet spend, deployments, destructive commands, token launches, marketplace work, social actions, and credential-sensitive operations.
  • Exposes checkout-url for the private local package and x402-evaluate-url for the paid workflow API.
  • Adds the package checkout and paid API to every completed GitHub job summary.
  • Rejects secret-key patterns and enforces the five-action / 20 KB hosted-evaluator bound.
  • Supports configurable fail-on behavior.

GitHub-hosted smoke run

Both stable tags point to the tested Action source:

  • v1 -> f554834849a3223a24aba117386bd53893841a4b
  • v1.0.1 -> f554834849a3223a24aba117386bd53893841a4b

Inspect Before Buying

The sample reports 2 allow, 0 review, and 2 deny. Automated tests prove that all 13 advertised buyer-relevant files exist in the paid tarball and that the policy engine, report formatter, and example manifest are byte-identical to the archive copies.

Private Workflow Routes

Current Verification

  • Production deployment: dpl_5NGPaGLkQU8V4rr4S25kVicmEYCD
  • Public launch commit: 4a40e76a55b7be66da0198e8977eb7a2576bf194
  • GitHub Pages workflow: 30061589933 succeeded
  • Product tests: 59/59 passed
  • Dependency audit: 0 vulnerabilities
  • Buyer preflight: all 6 checks passed
  • Paid package SHA-1: c67fb09bd83da591c58ae5fae002a6a59557fc97
  • Paid package size: 122737 bytes

The hosted evaluator receives the submitted manifest. Do not send secrets, private source, credentials, or sensitive customer data. Use the paid local package for private manifests.

Payment completion is recognized only from qualifying onchain Base USDC transfer evidence or the live verifier.