GitHub Actions workflow YAML checker
Paste a workflow file and get an instant review of the mistakes that break runs or open security holes: missing runs-on, unpinned third-party actions, risky pull_request_target use, missing permissions, script injection and invalid needs.
- Errors
- 4
- Warnings
- 5
- Notes
- 3
build has no runs-on:.runs-on: ubuntu-latest
pull_request_target combined with a checkout of the pull request head runs untrusted code with secrets (a classic supply-chain hole).Check out the base ref, or split into an unprivileged `pull_request` workflow plus a `workflow_run` follow-up.
${{ ... }} value is interpolated into a run: step in job build.Pass it through `env:` and reference "$VAR" in the script.
test needs lint, which is not defined. Jobs: build, test.pull_request_target runs with a write token and secrets in the context of the base repository. Never check out or run code from the pull request with it.Use `pull_request` unless you need secrets for labeling or commenting.
permissions:. The token defaults to the repository's setting, which may be read-write. Declare the least privilege.permissions: contents: read
build sets no permissions: and there is no workflow-level default.some-org/deploy-action@v2 is pinned to a tag, which can be moved. Pin to a full commit SHA.some-org/deploy-action@<40-char sha> # v2
test sets no permissions: and there is no workflow-level default.build has no timeout-minutes; the default is 360 minutes, so a hung job can burn a lot of CI time.timeout-minutes: 15
actions/checkout@v4 uses a tag; GitHub-owned actions are lower risk, but a SHA pin is stricter.test has no timeout-minutes; the default is 360 minutes, so a hung job can burn a lot of CI time.timeout-minutes: 15
Everything runs in your browser; nothing you type is sent anywhere.
How to use it
- Paste your workflow YAML into the box. The example already contains several problems.
- Read the findings, grouped as errors, warnings and notes, with line numbers where we can tell.
- Apply the suggested fixes and paste again until the list is clear.
Frequently asked questions
Does this upload my workflow?
No. Parsing and checks run in your browser. The only code loaded is a small YAML parser, and only on this page.
Is this a full schema validator?
No. It checks the mistakes we see most often and the ones with security impact. Use actionlint in CI for exhaustive validation.
Why pin actions to a commit SHA?
Tags and branches can be moved by the action's owner or an attacker who compromises it. A full commit SHA is immutable, so your pipeline only changes when you change it.
Why is pull_request_target dangerous?
It runs with a write token and secrets even for pull requests from forks. If it checks out and runs the pull request's code, an outsider can run code with your secrets.
Made by compiler.dev, faster GitHub Actions runners. More free tools.
Related tools
- GitHub Actions matrix expanderSee every job a GitHub Actions strategy.matrix creates, with include and exclude applied, and the total job count against the 256-job limit.
- GitHub Actions cron builder and explainerBuild and explain a GitHub Actions schedule cron expression. See it in plain English and the next 10 runs in UTC and your local time.
- GitHub Actions cache key builderBuild a correct actions/cache key with hashFiles patterns and restore-keys for npm, pnpm, pip, Gradle, Maven, Go, Cargo and more. Copy-ready YAML.
- Dependabot config generatorGenerate a dependabot.yml for npm, pip, Docker, GitHub Actions, Go, Cargo and more, with schedule, grouping, labels and reviewers. Validated, copy-ready.