Repository navigation
[lockfile-stats] Lockfile Statistics Analysis — 2026-10-06 #66276
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #66681. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-10-06
Overview: Analyzed all 323
.github/workflows/*.lock.ymlfiles (0 skipped). Combined size ~49.0 MB (avg 155.2 KB/file, range 86.6 KB–254.3 KB). No prior history was found in cache-memory, so this run establishes the baseline for future trend comparisons.Key metrics
workflow_dispatchpresentschedulepresentcreate_discussionwritepermsafeoutputsin 299 workflows)Trigger analysis
Top combinations:
schedule+workflow_dispatch(215),workflow_dispatchonly (54),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Full trigger and cron breakdown
Most common cron:
0 0 */2 * *(every 2 days at midnight) — shared by 46 workflows. Next most frequent crons each appear 2–3 times, otherwise highly diverse.Safe outputs analysis
Five baseline types appear in 316/323 workflows (97.8%) —
noop,missing_data,missing_tool,report_incomplete,create_report_incomplete_issue— consistent with shared compiler-injected scaffolding rather than per-workflow choice.Safe output type frequency (top 15 of 55)
40 additional long-tail types appear 1–7 times each (e.g.
jira_*,linear_create_issue,send-slack-message).Discussion categories (92 resolved of 93
create_discussionworkflows):audits79,announcements5,artifacts2,dev2,research2,general1,daily-news1. One workflow —pr-sous-chef.lock.yml— could not be resolved by either the JSON config path or the regex fallback (safe_outputs_config_missing: 1); flagged for manual follow-up.Structural characteristics
run:) stepsAverage ~7.2 jobs and ~145 steps per workflow; script steps make up ~44% of all steps.
Job-level
timeout-minutesvalues cluster tightly: 10 min (362 jobs), 45 min (323 jobs), 60 min (316 jobs) — these counts track closely with per-workflow job roles (detection/safe-output/agent jobs), suggesting standardized timeout tiers across the fleet.Permission patterns (agent job)
permissions_unknown: 0 — every lockfile's agent-job permissions were resolved.Union across all jobs per workflow (any job granting write):
issueswrite in 323/323 (100%) workflows,contentswrite in 213 (65.9%),copilot-requestswrite in 148 (45.8%),pull-requestswrite in 147 (45.5%),discussionswrite in 97 (30.0%). All 323 workflows (100%) grant some write scope via a dedicated safe-output writer job, even though per-engine agent jobs themselves stay read-only oncontents.Engine distribution
(from
gh-aw-metadataagent_id, 0 unresolved)Tool & MCP patterns
safeoutputsMCP server appears in 299 workflows (92.6%),githubin 181 (56.0%),agenticworkflowsin 26,mcpscriptsin 19,serenain 17. Long tail:work-queue(6),tavily(3),sentry(2), and 7 servers used once each (kreuzberg,graft,ast-grep,grafana,ruflo,deepwiki,microsoftdocs). 7 workflows required the legacy# - mcp__...comment fallback instead of the structured manifest.Interesting findings
issues:write— all 323 workflows (100%) grant some jobissues: write, even though only 166 (51%) actually usecreate_issueas a safe output. This points to the safe-output writer job requesting a fixed permission set regardless of which outputs a workflow actually emits — a candidate for least-privilege tightening.auditsis the dominant discussion category — 79 of 92 resolved categories (85.9%), reflecting that audit-style reporting agents (like this one) are the heaviest users ofcreate_discussion.copilot-requests: write(a non-standard, Copilot-specific permission scope) appears in 148 workflows (45.8%) — nearly half the fleet is tracking premium request budgets.copilotleads at 41% butcodex,claude, andpicollectively account for the majority of the remainder, indicating ongoing cross-engine experimentation rather than consolidation on one runtime.Historical trends
No prior summary existed in
/tmp/gh-aw/cache-memory/history/— this run is the baseline. Future runs will diff against2026-10-06.json.Recommendations
issues: writeis granted in 100% of workflows regardless of configured safe outputs; scope the writer job's permissions to the safe-output types actually declared per workflow.pr-sous-chef.lock.yml, the one workflow whereGH_AW_SAFE_OUTPUTS_CONFIGcould not be parsed by either the primary or fallback path.0 0 */2 * *cron to reduce simultaneous-trigger load on shared runners.Methodology: single-script compact JSON analysis (
lockfile_stats_v4.py, cached under/tmp/gh-aw/cache-memory/scripts/).References:
All reactions