Repository navigation
[lockfile-stats] Lockfile Statistics Analysis — 2026-10-08 #66993
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #67273. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-10-08
Analyzed 333 compiled lockfiles in
.github/workflows/*.lock.yml(0 skipped/malformed). Total size 50.8 MB, avg 156.2 KB/file (min 87.1 KB, max 281.3 KB).File size distribution
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(210),workflow_dispatchonly (68),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Top cron frequency:
0 0 */2 * *(every 2 days at midnight) — 50 workflows. All other distinct cron strings appear 2-3 times (highly staggered schedules).Safe outputs analysis
Standard scaffolding (
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issue) present in 326/333 workflows (97.9%). Beyond scaffolding, by frequency:Discussion categories (93 workflows configure
create_discussion; category resolved for 92/93 = 98.9%):Unresolved:
pr-sous-chef.lock.yml— noGH_AW_SAFE_OUTPUTS_CONFIGenv var found (likely a stale compiled lockfile; also the solesafe_outputs_config_missingcase in the corpus).Structural characteristics
run) stepsPermission patterns (agent job)
permissions_unknown: 0— every lockfile's agent-job permissions resolved cleanly.Union (any job) write grants — 330/333 workflows (99.1%) grant write on at least one scope: issues (330), contents (212), copilot-requests (157), pull-requests (146), discussions (96), actions (125), checks (14), id-token (3), others ≤3.
Engine distribution
engine_unknown: 0— every lockfile's engine resolved viagh-aw-metadataagent_id(or fallback).Tool & MCP patterns
7 lockfiles required legacy fallback parsing (
# - mcp__...comments) instead of agh-aw-manifestJSON block.Interesting findings
workflow_dispatch, and the dominant comboschedule+workflow_dispatch(210, 63%) shows almost every scheduled workflow is also manually runnable.agyengine is a new entrant this period (0→3), paired with a newagy-nativeMCP server (0→3).work-queueMCP usage nearly tripled day-over-day (6→16, +167%), the largest relative mover in the tool/MCP data — suggests a cluster of workflows adopted shared work-queue coordination recently.auditsdominates discussion categories (79/92, 85.9% ofcreate_discussionworkflows) — consistent with a large population of reporting/audit-style workflows like this one.copilot-requestswrite scope granted to 157 workflows (47%) — not a standard GitHub Actions permission scope, almost certainly Copilot-engine-specific usage/billing tracking; worth a sanity check that it's intentional and scoped only to Copilot-engine workflows.pr-sous-chef.lock.yml) had unresolved safe-outputs/discussion-category detection — 99.7% full extraction coverage across the corpus.Historical trends (vs. 2026-10-07)
No change in discussion category distribution day-over-day.
Recommendations
pr-sous-chef.lock.yml— itsGH_AW_SAFE_OUTPUTS_CONFIGcould not be located; likely needs agh aw compilerefresh.copilot-requeststo confirm the scope is intentional and limited to Copilot-engine workflows.work-queueMCP adoption spike (+167% day/day) and the newagyengine entrant in future reports to see if these represent an ongoing migration.Methodology note
Single-script compact JSON analysis: one Python script parsed all
.lock.ymlfiles viayaml.safe_load, extracting engine/permissions/safe-outputs fromgh-aw-metadata/gh-aw-manifestcomments and theGH_AW_SAFE_OUTPUTS_CONFIGenv var (not the always-empty top-levelpermissions: {}), then wrote one compact summary JSON consumed for this report.All reactions