Repository navigation
[lockfile-stats] Lockfile Statistics Audit — 2026-10-07 #66681
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #66993. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Overview: 327 compiled workflow lockfiles (
.github/workflows/*.lock.yml), 0 malformed/skipped. Total size 52,101,388 bytes (~49.7 MB), avg 159,332 bytes, min 87,611, max 259,679. +4 lockfiles vs. 2026-10-06.Key metrics
workflow_dispatch319 (97.6%),schedule251 (76.8%),pull_request43 (13.1%)schedule+workflow_dispatch218 (66.7%)noop/missing_tool/missing_data/report_incomplete) in 320 workflows;create_issue170,create_discussion92,add_comment74,create_pull_request65audits79,announcements5,artifacts2,dev2,research2,general1,daily-news1 (92/93 resolved)copilot-requests(154) andid-token(3) —contents/issues/pull-requestsare read-only at the agent job in every casesafeoutputs303,github181,agenticworkflows27,mcpscripts22,serena17, 7 lockfiles via comment-scrape fallbackFile size distribution
Trigger analysis
Top combinations:
schedule+workflow_dispatch218,workflow_dispatchonly 55,pull_request+schedule+workflow_dispatch29,pull_request+workflow_dispatch9,pull_request3.Cron clustering:
0 0 */2 * *appears in 50 of 251 scheduled workflows (~20%) — by far the most common single cron expression; the remaining top crons each appear 2–3 times.Safe outputs analysis
Baseline tools present in ~98% of workflows:
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issue(320 each).Content-producing types:
create_issue170,create_discussion92,add_comment74,create_pull_request65,push_repo_memory35,add_labels32,upload_asset26,mentions23,create_pull_request_review_comment/submit_pull_request_review16 each.Long tail (1 workflow each): Jira (
jira_add_comment,jira_add_label,jira_create_issue,jira_update_issue),linear_create_issue, Slack variants,create_project_status_update,update_project, etc.create_discussion_workflows= 93,discussion_category_detected= 92 (99%). One unresolved:pr-sous-chef.lock.yml(same file unresolved on both 10-06 and 10-07 — likely a non-literal/dynamic category value).safe_outputs_config_missing= 1 lockfile.Structural characteristics
Permission patterns (agent job + job-union)
Union-of-jobs write grants:
issues327,contents212,copilot-requests154,pull-requests146,discussions96,actions117,checks14,id-token3.workflows_with_any_write= 327/327 (100%),permissions_unknown= 0.The agent job itself never carries
writeoncontents/issues/pull-requests/discussions— all observed writes route through either a dedicated downstream job (e.g., a PR-push job) or the safe-outputs mechanism, not direct agent-job permissions.Engine distribution
engine_unknown= 0 (fully resolved viagh-aw-metadata).Tool & MCP patterns
mcp_fallback_count= 7 lockfiles required comment-scrape fallback (nomcp_serversin manifest).Interesting findings
copilot-requests(154) andid-token(3) — nevercontents/issues/pull-requestsat the agent job. This confirms the safe-outputs architecture is holding across the whole fleet, not just a subset.0 0 */2 * *covers ~20% of all scheduled workflows (50/251), far more than any other expression — likely a copy-pasted default rather than intentional scheduling, and a candidate for staggering to avoid synchronized runner contention.pr-sous-chef.lock.ymlis the onlycreate_discussionworkflow whose category wasn't statically resolvable, and it's been that way for at least two consecutive days — worth checking whether its category is set via a dynamic expression rather than a literal string.Historical trends (2026-10-06 → 2026-10-07)
The 4 new lockfiles didn't adopt
create_discussion(category distribution unchanged), and newer workflows trend toward slightly narrowerissues/pull-requestsread grants relative to the growing lockfile count.Recommendations
0 0 */2 * *cron cluster across times/days to reduce simultaneous runner load.pr-sous-chef.lock.yml's unresolvedcreate_discussioncategory — confirm it's intentional (dynamic value) rather than a misconfiguration.contents/issues/pull-requestswrite at the agent job — the current 100% read-only-at-agent pattern is a strong security baseline worth preserving.Methodology: single-script compact JSON analysis (
lockfile_stats_v4.py, cached at/tmp/gh-aw/cache-memory/scripts/), parsinggh-aw-metadata/gh-aw-manifestheader comments andGH_AW_SAFE_OUTPUTS_CONFIGenv JSON per lockfile; no full-file greps outside the analyzer.References: §37681896110
All reactions