[lockfile-stats] Lockfile Statistics — 2026-09-28 #64080
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #64341. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
298 compiled workflow lockfiles analyzed, 46.85 MB total (0 malformed, 0 unresolved engine/permission/discussion-category detections).
File size distribution
Sizes cluster tightly around the ~157 KB average (min 93 KB, max 251 KB) — a ~2.7x spread, consistent with most workflows sharing the same compiled scaffolding (safe-outputs handlers, MCP wiring) with variable amounts of custom prompt/tool config layered on top.
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(209),workflow_dispatchonly (37),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Cron cadence: the dominant schedule is
0 0 */2 * *(every 2 days) at 42 workflows; the remaining ~30 distinct cron expressions each appear 1-3 times, indicating most scheduled workflows are hand-tuned to avoid clustering at a single time.Safe outputs analysis
Every workflow ships the baseline safe-output tool set (
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issue— 292/298). Beyond the baseline:Discussion categories (92 workflows configure
create_discussion, all 92 resolved — 0 unresolved):auditsdominates at 79, followed byannouncements(5),artifacts/dev/research(2 each),general/daily-news(1 each). This audit itself lands inaudits.Structural characteristics
uses:actions10min appears 353 times (per-job granularity, so more than one 10-min job per workflow is common),45min on all 298 (likely the agent job default),60min on 291Permission patterns (agent job, not top-level)
Agent jobs are read-mostly:
contents: readuniversally (298/298),issues: read(259) / none (39),pull-requests: read(254) / none (44),discussions: readonly 52 (246 none). No agent job carries write permissions directly.The union across all jobs in each workflow tells a different story — every single workflow (298/298) grants at least one write scope somewhere in its job graph, most commonly
issues: write(all 298) andcontents: write(205). This is expected: safe-output "apply" jobs (separate from the sandboxed agent job) need write access to actually create issues/PRs/discussions, while the agent job itself stays read-only — the intended security boundary in gh-aw's design.Engine distribution
Copilot leads at 41%, codex 25%, claude 19%. All 298 engines resolved (0 unknown).
Models:
openai/gpt-5.3-codex(37) andcopilot/gpt-5.3-codex(33) are the top two explicit picks;copilot/auto(30) is the most common auto-select. A handful of workflows (3) parameterize model choice via${{ needs.activation.outputs.model_size }}.Tool & MCP patterns
Every workflow uses the
safeoutputsMCP server (298/298).githubMCP is used by 174 workflows,agenticworkflowsby 44,serenaby 25. Long tail:mcpscripts(12),tavily(5),sentry(4), plus single-digit usage ofast-grep,datadog,deepwiki,microsoftdocs,grafana,kreuzberg,mempalace,graft,agentdb,ruflo.Most-called individual tools:
safeoutputs:missing_data/missing_tool/noop(292 each, baseline),github:get_commit/get_file_contents/get_latest_releasefamily (166 each),safeoutputs:create_issue(145),github:get_me(142).Interesting findings
auditsis by far the dominant category (79 of 92), suggesting most discussion-producing workflows are themselves reporting/audit agents like this one.Historical trends (vs 2026-09-27)
Lockfile count unchanged (298 → 298). Total size grew marginally: +2,044 bytes (46,843,837 → 46,845,881), consistent with minor content edits rather than structural changes (no new/removed workflows, trigger/engine/permission distributions identical day-over-day).
Recommendations
Methodology: single-script compact JSON analysis (cached analyzer at
/tmp/gh-aw/cache-memory/scripts/lockfile_stats_v4.py, reused from a prior run; see<safe-output-tools>history in/tmp/gh-aw/cache-memory/history/).All reactions