Repository navigation
[lockfile-stats] Lockfile Statistics Audit — 2026-10-04 #65664
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-05T21:08:27.641Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Analysis of 320 compiled
.github/workflows/*.lock.ymlfiles (single-script compact JSON analysis, 0 malformed/skipped).Executive summary
File size distribution
Range 83.8 KB – 250.1 KB, tight clustering around the 152 KB average — lockfiles are dominated by boilerplate (safe-output tool defs, MCP tool lists) rather than per-workflow logic.
Trigger analysis
Top combinations:
schedule+workflow_dispatch(217, +1), soloworkflow_dispatch(51),pull_request+schedule+workflow_dispatch(29). Most common cron:0 0 */2 * *(46 workflows, every 2 days). Notably7 5 * * *grew from 3→4 workflows day-over-day.Safe outputs analysis
Every workflow includes the standard safe-output control set (
missing_data/missing_tool/noop/report_incomplete/create_report_incomplete_issue, ~313 each). Beyond those:Discussion categories (92
create_discussionworkflows, 100% resolved, 0 unresolved):audits(79),announcements(5),artifacts/dev/research(2 each),general/daily-news(1 each).safe_outputs_config_missing= 1 (consistent with prior day).Structural characteristics
Timeout-minutes distribution: 10min (359 jobs), 45min (320), 60min (313) dominate; long tail at 90/120/180/15/5/3 min.
Permission patterns (agent job)
Agent jobs are read-only almost everywhere — writes happen via the
safeoutputsMCP server, not direct job permissions. Union-across-jobs tells the real write story: all 320 workflows grantissues: writesomewhere in the job graph (safe-output processing jobs), 211 grantcontents: write, 147 grantpull-requests: write, 97 grantdiscussions: write.Engine distribution
engine_unknown= 0 — every lockfile'sagent_idresolved cleanly fromgh-aw-metadata.copilot/auto(16) is the single most common model config; the model field is highly fragmented (49+ distinct values) across date-coded model names (gpt-6.1-sol,gpt-5.6-terra, etc.) and provider-prefixed variants.Tool & MCP patterns
mcp_fallback_used_count= 0 — all manifests parsed viagh-aw-manifestJSON, no legacy scraping needed. Most-used individual tools:safeoutputs:missing_data/missing_tool/noop(314 each), 15 distinctgithub:*read tools at 174–184 each (commits/releases/tags/PRs),safeoutputs:create_issue(165).Interesting findings
safeoutputsMCP server and a dedicated write-permission job, visible only in the union-of-jobs view — auditing the top-level/agent permissions alone would badly understate write exposure.copilotjust overtook the field at 130/320 (40.6%) as the single largest engine share, ahead ofcodex(78) andclaude(57) combined with second place.create_discussionworkflows resolved a category (79 toauditsalone), with zero fallback-regex parses needed — the structuredGH_AW_SAFE_OUTPUTS_CONFIGextraction path is fully reliable across the fleet.agent_modelstrings for only 13 distinct engines, including a literal unresolved template token (${{ needs.activation.outputs.model_size }}, 3 occurrences) — suggests some lockfiles compile with dynamic model selection left unexpanded.scheduletrigger, and0 0 */2 * *alone accounts for 46 — a strong clustering that could be spread out to reduce simultaneous Actions-minute contention.Historical trends (vs 2026-10-03)
Growth was incremental and uniform: +1 lockfile, +1
workflow_dispatch/scheduletrigger, +1create_issue/create_pull_request/upload_artifact/upload_asset(unchanged)/copilotengine — consistent with a single new workflow added using thecopilotengine withcreate_issue+create_pull_request+upload_artifactsafe outputs and schedule+workflow_dispatch triggers. No regressions in discussion-category resolution or engine detection (both still 0 unresolved/unknown).Recommendations
0 0 */2 * *(46 workflows) across more offsets to reduce runner contention.agent_modelnaming (49+ variants for 13 engines) and ensure${{ needs.activation.outputs.model_size }}-style expressions are resolved before compilation, or confirm they're intentionally dynamic.Methodology note
Single-script compact JSON analysis:
.github/workflows/*.lock.ymlparsed once via a cached PyYAML-based analyzer (lockfile_stats_v4.py), producing a ~9 KB compact JSON summary subsequently reasoned over without reopening individual lockfiles.All reactions