Mutable action references
Spot actions that can change underneath a workflow.
ActionFix statically analyzes GitHub Actions workflows for risky configurations and helps you understand what needs to change.
Public repository scanner coming soon.
What it looks for
Focused analysis for the configurations that are easy to miss and important to get right.
Spot actions that can change underneath a workflow.
Understand when workflow permissions are broader than needed.
Surface dangerous pull request, expression, and runner patterns.
A deliberate boundary
ActionFix analyzes workflow configuration as data. It does not clone and execute repository code, actions, scripts, or containers.
Product status