[lockfile-stats] Lockfile Statistics Analysis — 2026-09-27 (298 lockfiles, flat vs prior day) #63877
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #64080. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-09-27
Analysis of all
.github/workflows/*.lock.ymlcompiled workflow files in this repo.Overview: 298 lockfiles, ~44.7 MB total, avg 153.5 KB each. All parsed cleanly (0 skipped). Fleet composition and permission patterns are nearly unchanged from the prior snapshot (2026-09-26).
Key metrics
workflow_dispatchenabledscheduleenabledcreate_discussionFile size distribution
Avg 157.2 KB, min 93.0 KB, max 250.7 KB — a fairly tight spread (~2.7x max/min), consistent with a shared compiled-workflow scaffold plus per-workflow logic.
Trigger analysis
Trigger counts and top combinations
Top combinations:
schedule+workflow_dispatch(209, 70%),workflow_dispatchonly (37, 12%),pull_request+schedule+workflow_dispatch(29, 10%),pull_request+workflow_dispatch(9).Cron cadence is dominated by one pattern:
0 0 */2 * *(every 2 days) appears 42 times (17% of all scheduled workflows); the remaining ~200 scheduled workflows spread across dozens of distinct, largely unique cron expressions.Safe outputs analysis
Safe-output type frequency (top entries)
Near-universal scaffolding:
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issueeach appear in 292/298 workflows (98%) — a de facto standard safe-output baseline across the fleet (this workflow included).Feature safe outputs:
create_issue145 (49%),create_discussion92 (31%),add_comment76 (26%),create_pull_request64 (21%),push_repo_memory36,add_labels32,upload_asset26, then a long tail down to single-use integrations (Jira, Linear, Slack).Discussion categories (92 workflows, 100% detected, 0 unresolved, 0 fallback-parsed):
audits79 (86%),announcements5,artifacts2,dev2,research2,general1,daily-news1.Structural characteristics
Timeout minutes across all jobs: 10min (353 jobs), 45min (298), 60min (291), 90min (3), 5min (2), 120min (2), 180min (1), 15min (1) — the 45/60/10-minute triad is essentially universal per workflow.
Permission patterns
(derived from
jobs.agent.permissionsand per-job union — the top-levelpermissions: {}carries no signal and was not used)Agent job (primary, mirrors frontmatter) —
contents: read100%;issuesread 87% / none 13%;pull-requestsread 85% / none 15%;actionsread 38% / none 62%;discussionsread 17% / none 83%;id-token: writeonly 2 workflows; all other scopes (checks,pages,statuses,repository-projects,attestations) arenonein essentially all workflows.Union across all jobs —
issues: writein 298/298 (100%) and some write scope present in 298/298 workflows, even though only 145 configurecreate_issue— write access is provisioned defensively at the job-graph level, not only where a matching safe output is configured.contentsis write in 205 (69%) / read in 93 (31%);discussions: writein 96 (roughly tracking the 92create_discussion+ a fewclose_discussionconfigs).Engine distribution
(from
gh-aw-metadataagent_id, 0 unresolved)copilot 123 (41%), codex 74 (25%), claude 56 (19%), pi 31 (10%), aider 3, goose 3, opencode 2, crush/cursor/deepseek-harness/gemini/kiro/pydantic-ai 1 each — a genuinely multi-engine fleet rather than one engine dominating.
Notable model field: 3 workflows resolve their model via a templated expression (
${{ needs.activation.outputs.model_size }}) rather than a static model id.Tool & MCP patterns
safeoutputsMCP server: 298/298 (100%, universal).github: 174 (58%).agenticworkflows: 44 (15%).serena: 25 (8%). Long tail: mcpscripts, tavily, sentry, ast-grep, datadog, deepwiki, microsoftdocs, grafana, and single-use servers (kreuzberg, mempalace, graft, agentdb, ruflo). 0 workflows required fallback (non-manifest) tool detection.Interesting findings
issues: writeand some write scope at the job-graph level, even though only 145 configurecreate_issueas a safe output — permissions are provisioned by the safe-output application layer uniformly, not per-feature.0 0 */2 * *) accounts for 17% of all scheduled workflows; the rest are individually tuned.create_discussionworkflows (79/92) post toaudits, same as this report.missing_data/missing_tool/noop/report_incomplete/create_report_incomplete_issue), indicating a shared compiled template rather than per-workflow opt-in.Historical trends
Compared to the prior snapshot (2026-09-26): lockfile count unchanged (298 → 298); total size grew marginally (+6,830 bytes, +0.01%, avg size +22.9 bytes/file). All trigger, safe-output, engine, permission, timeout, and MCP distributions are identical byte-for-byte to the prior day — no structural change, only a trivial content edit in one or two lockfiles.
Recommendations
issues: writeis granted universally regardless of whethercreate_issueis configured, consider scoping the safe-output-apply job's permissions to only the safe outputs actually enabled per workflow, to reduce blast radius.auditsdiscussion category is heavily concentrated (86%); if category diversity is desired, review whether other categories are underused by convention or by omission.${{ needs.activation.outputs.model_size }}) in 3 workflows is worth spot-checking to confirm it resolves to a valid, current model id at runtime.Methodology: single-script compact JSON analysis (cached analyzer, reused from prior run; self-checks passed: 0 skipped lockfiles, 0 engine-unknown, 0 permissions-unknown, 92/92 discussion categories detected, 0 safe-outputs-config-missing).
References:
All reactions