[lockfile-stats] Lockfile Statistics Report — 2026-09-22 #62746
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #63025. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Analysis of 299 compiled
.github/workflows/*.lock.ymlfiles ingithub/gh-aw, generated via single-script compact JSON analysis. 0 lockfiles skipped as malformed.Executive summary
workflow_dispatchschedulecreate_discussionworkflowsFile size distribution
Trigger analysis
Top individual triggers:
Top trigger combinations:
Schedule cadence: the dominant cron is
0 0 */2 * *(every 2 days) at 42 workflows — far ahead of any other single cron pattern (next highest: 3 occurrences). Most other crons are unique per-workflow daily/weekday schedules.Safe outputs analysis
Every workflow ships the standard safety trio (
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issueat 293/299 — 6 workflows lack these, worth spot-checking).Top domain-specific safe outputs:
Discussion categories (92
create_discussionworkflows, 92/92 detected — 100%, no unresolved cases):Detection status: not a failure case —
create_discussion_workflows(92) anddiscussion_category_detected(92) match exactly, with 0 fallback-regex parses needed.safe_outputs_config_missing= 0.Structural characteristics
Permission patterns
Based on
jobs.agent.permissions(the primary per-workflow scope, mirroring frontmatter — not the always-empty top-levelpermissions: {}):The agent job itself never holds
writeon any scope exceptid-token(2 workflows) — consistent with the safe-outputs pattern where writes happen via a separate downstream job.Union across all jobs (any job in the workflow, e.g. the safe-output-processing job) tells the real write story: all 299 workflows grant
writeonissuessomewhere in the job graph, 206 grantcontents: write, 146 grantpull-requests: write, and 96 grantdiscussions: write. All 299 workflows have at least one job with a write scope (union_any_write_count: 299).Engine distribution
0 lockfiles had an unresolved engine (all identified via
gh-aw-metadataagent_id).Tool & MCP patterns
MCP servers in use:
Most-used individual tools:
github:get_commit,get_file_contents,get_latest_release,get_release_by_tag,get_tag,list_branches,list_commits,list_releases,list_starred_repositories,list_tags,search_code,search_repositoriesare tied at 166 workflows each (likely granted as a bundled read-only toolset). All MCP data came from thegh-aw-manifestcomment — 0 workflows required the legacy fallback parser.Interesting findings
workflow_dispatch) and 81% run on a schedule — this repo's workflows are overwhelmingly autonomous/scheduled rather than purely event-reactive.auditsdominates discussion categories (79 of 92, 86%) — this very report is one of them, suggesting the audits category is the primary reporting channel for automated analysis workflows.id-tokenin 2 workflows), while writes are consistently delegated to a separate job — a clean least-privilege pattern held across the entire fleet.github:*tools strongly suggests a shared/bundled tool-group definition rather than per-workflow hand-picking.Historical trends (vs. 2026-09-21)
Net effect: one workflow appears to have switched engine from
opencodetocopilot(or an equivalent net change), alongside modest growth in average lockfile size — consistent with incremental workflow edits rather than a bulk change.Recommendations
noop/missing_tool/missing_datasafety trio (293 vs. 299 lockfiles) to confirm this is intentional.pull-requestspermission and 185 withoutactionspermission need it, given how many downstream jobs already carrywritethere — tightening/loosening should be a deliberate, not incidental, choice.auditscategory already holds 79 discussions, consider whether it needs sub-categorization as the audit workflow count grows.Methodology: single-script compact JSON analysis (analyzer cached at
/tmp/gh-aw/cache-memory/scripts/lockfile_stats_v4.py, summary written to compact JSON, historical comparison against2026-09-21).Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
All reactions