[lockfile-stats] Lockfile Statistics — 2026-09-29 (300 workflows analyzed) #64341
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-09-30T20:34:09.346Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-09-29
Analysis of all
.github/workflows/*.lock.ymlcompiled workflow files ingithub/gh-aw, generated by a single-script compact-JSON analyzer (schema v4).At a glance: 300 lockfiles · 44.9 MB total · 0 malformed/skipped · 0 unresolved engine/permission/discussion-category detections.
Executive summary
workflow_dispatchFile size distribution
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(211, 70.3%),workflow_dispatchalone (37),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Cron cadence: the dominant schedule is
0 0 */2 * *(every 2 days at midnight) — 43 workflows, far ahead of the next most common patterns (2–3 occurrences each).Safe outputs analysis
Nearly universal safety scaffolding:
noop,missing_data,missing_tool, andreport_incomplete/create_report_incomplete_issueeach appear in 294/300 workflows (98%).Discussion categories (92 workflows, 92/92 resolved):
Structural characteristics
run:) steps per workflowPermission patterns
Agent job (
jobs.agent.permissions— the primary per-workflow scope, mirrors frontmatter):Every workflow's agent job has read-only (or none)
contents— no agent job writes directly. Actual writes are isolated to dedicated safe-output jobs: the union of all jobs per workflow showsunion_any_write_count = 300/300— every single workflow has some job with write access somewhere (issues:write in all 300), confirming the safe-outputs security boundary (agent job read-only → separate writer job scoped to write) is applied consistently, not just in a subset.Engine distribution
Top models:
openai/gpt-5.3-codex(37),copilot/gpt-5.3-codex(34),copilot/auto(30),openai/gpt-5.4(11),claude-sonnet-5(6).Tool & MCP patterns
14 other servers (ast-grep, datadog, deepwiki, microsoftdocs, grafana, kreuzberg, mempalace, graft, agentdb, ruflo, ...) each appear in ≤2 workflows.
Interesting findings
noop/missing_data/missing_tool/report_incompletesafe-output set, indicating a shared generator/template enforces this baseline rather than per-workflow authors adding it manually.contents, yet every workflow has a write-capable job somewhere (union), which is exactly the intended safe-outputs isolation model with zero exceptions found.auditscategory (this report included), suggesting the audits pipeline is now the primary consumer ofcreate_discussion.0 0 */2 * *alone accounts for 43 workflows, more than 14x the next-most-common cron string, pointing to a shared "every-other-day" default rather than organic diversity in scheduling.Historical trends (vs. 2026-09-27)
Growth is incremental (+2 workflows) with flat average size — new workflows are in line with the existing size profile, not driving bloat.
Recommendations
id-token: writeand the few grantingattestations/packageswrite to confirm OIDC/provenance use is deliberate.Methodology
Single-script compact JSON analysis: one Python pass over all
.github/workflows/*.lock.ymlfiles extracts engine metadata from thegh-aw-metadataheader, MCP servers from thegh-aw-manifestheader, safe-output config fromGH_AW_SAFE_OUTPUTS_CONFIG, and per-job permissions fromjobs.*.permissions(the top-levelpermissions: {}block carries no signal and was ignored). Self-checks confirmed 0/300 unresolved engines, 0/300 unresolved permissions, and 92/92 resolved discussion categories.References:
All reactions