Skip to content
compiler.dev

GitHub Actions workflow YAML checker

Paste a workflow file and get an instant review of the mistakes that break runs or open security holes: missing runs-on, unpinned third-party actions, risky pull_request_target use, missing permissions, script injection and invalid needs.

Errors
4
Warnings
5
Notes
3
Error (line 6): Job build has no runs-on:.
runs-on: ubuntu-latest
Error (line 10): pull_request_target combined with a checkout of the pull request head runs untrusted code with secrets (a classic supply-chain hole).
Check out the base ref, or split into an unprivileged `pull_request` workflow plus a `workflow_run` follow-up.
Error (line 12): Script injection: an untrusted ${{ ... }} value is interpolated into a run: step in job build.
Pass it through `env:` and reference "$VAR" in the script.
Error (line 13): Job test needs lint, which is not defined. Jobs: build, test.
Warning (line 3): pull_request_target runs with a write token and secrets in the context of the base repository. Never check out or run code from the pull request with it.
Use `pull_request` unless you need secrets for labeling or commenting.
Warning (line 1): No top-level permissions:. The token defaults to the repository's setting, which may be read-write. Declare the least privilege.
permissions:
  contents: read
Warning (line 6): Job build sets no permissions: and there is no workflow-level default.
Warning (line 11): Third-party action some-org/deploy-action@v2 is pinned to a tag, which can be moved. Pin to a full commit SHA.
some-org/deploy-action@<40-char sha> # v2
Warning (line 13): Job test sets no permissions: and there is no workflow-level default.
Note (line 6): Job build has no timeout-minutes; the default is 360 minutes, so a hung job can burn a lot of CI time.
timeout-minutes: 15
Note (line 8): actions/checkout@v4 uses a tag; GitHub-owned actions are lower risk, but a SHA pin is stricter.
Note (line 13): Job test has no timeout-minutes; the default is 360 minutes, so a hung job can burn a lot of CI time.
timeout-minutes: 15

Everything runs in your browser; nothing you type is sent anywhere.

How to use it

  1. Paste your workflow YAML into the box. The example already contains several problems.
  2. Read the findings, grouped as errors, warnings and notes, with line numbers where we can tell.
  3. Apply the suggested fixes and paste again until the list is clear.

Frequently asked questions

Does this upload my workflow?

No. Parsing and checks run in your browser. The only code loaded is a small YAML parser, and only on this page.

Is this a full schema validator?

No. It checks the mistakes we see most often and the ones with security impact. Use actionlint in CI for exhaustive validation.

Why pin actions to a commit SHA?

Tags and branches can be moved by the action's owner or an attacker who compromises it. A full commit SHA is immutable, so your pipeline only changes when you change it.

Why is pull_request_target dangerous?

It runs with a write token and secrets even for pull requests from forks. If it checks out and runs the pull request's code, an outsider can run code with your secrets.

Made by compiler.dev, faster GitHub Actions runners. More free tools.