Skip to content

Repository files navigation

check-workflow

Python Version from PEP 621 TOML GitHub Release GitHub License pre-commit.ci status

Check GHA For Dependency Updates

$ CheckWorkflow remote sco1 check-workflow
lint_test.yml
+-------------+-------------------------+---------------------------+-----------+--------+
|     Job     |        Step Name        |           Action          | Specified | Latest |
+-------------+-------------------------+---------------------------+-----------+--------+
|     lint    |           None          |      actions/checkout     |   4.0.0   | 5.0.0  |
|     test    |           None          |      actions/checkout     |   4.0.0   | 5.0.0  |
| combine-cov |           None          |      actions/checkout     |   4.0.0   | 5.0.0  |
| combine-cov | Pull workflow artifacts | actions/download-artifact |   4.0.0   | 5.0.0  |
+-------------+-------------------------+---------------------------+-----------+--------+

release.yml
+-------+-----------+------------------+-----------+--------+
|  Job  | Step Name |      Action      | Specified | Latest |
+-------+-----------+------------------+-----------+--------+
| build |    None   | actions/checkout |   4.0.0   | 5.0.0  |
+-------+-----------+------------------+-----------+--------+

Installation

Since this is mainly intended as a personal helper, there is no intent to deploy this project to PyPI. Wheels are built in CI for each released version.

Alternatively, you can use a tool like uv or pipx to run or install this project as a standalone tool, e.g.:

$ uvx --from git+https://github.com/sco1/check-workflow@v1.5.0 CheckWorkflow --help
usage: CheckWorkflow [-h] [-v] [-c COOLDOWN] {local,remote,bump,add_sha} ...

positional arguments:
  {local,remote,bump,add_sha}
    local               Query local project
    remote              Query remote repository
    bump                Bump local workflow dependencies
    add_sha             Replace version pins with SHA pins

options:
  -h, --help            show this help message and exit
  -v, --verbose         Increase log verbosity
  -c, --cooldown COOLDOWN
                        Dependency cooldown period, as PnD

Usage

Manual reports can be generated using the CheckWorkflow CLI for either a local or remote project.

All subcommands provide the ability to specify a dependency cooldown period as PnD, e.g. P7D will ignore any releases that are not at least 7 days old. Note that if your existing pins were specified without a cooldown in mind this may result in a "latest" result that is older than the current pin.

Local

Check for dependency updates for GHA workflows defined in the specified root.

$ CheckWorkflow local --help
usage: CheckWorkflow local [-h] [-r ROOT] [-m]

options:
  -h, --help       show this help message and exit
  -r, --root ROOT  Workflow root (default: ./.github/workflows/)
  -m, --markdown   Format report as markdown (default: False)

Remote

Check for dependency updates for GHA workflows defined by the specified GitHub repository.

$ CheckWorkflow remote --help
usage: CheckWorkflow remote [-h] [-b BRANCH] [-r ROOT] [-m] org repo

positional arguments:
  org                  Query repository parent
  repo                 Query repository

options:
  -h, --help           show this help message and exit
  -b, --branch BRANCH  Query branch (default: main)
  -r, --root ROOT      Workflow root (default: .github/workflows/)
  -m, --markdown       Format report as markdown (default: False)

Bump

Automatically bump the dependencies for workflows defined at the specified local root.

$ CheckWorkflow bump --help
usage: CheckWorkflow bump [-h] [-r ROOT] [--sha] [--dry-run]

options:
  -h, --help       show this help message and exit
  -r, --root ROOT  Workflow root (default: ./.github/workflows/)
  --sha            Pin to SHA (default: False)
  --dry-run        Preview the requested diff (default: False)

Add SHA

Convert existing version pins to the most recent SHA pin for workflows defined at the specified local root.

$ CheckWorkflow add_sha --help
usage: CheckWorkflow add_sha [-h] [-r ROOT] [--dry-run]

options:
  -h, --help       show this help message and exit
  -r, --root ROOT  Workflow root (default: ./.github/workflows/)
  --dry-run        Preview the requested diff (default: False)

Why Don't You Just Use Dependabot?

Because I don't want to! 😊

The idea initially came because Dependabot for a very long time did not support grouping PRs, which led to a ton of noise that I didn't particularly care for. Though it was eventually added, workflow updates aren't something I need to constantly be pinged on to take care of; it's sufficient for my needs to bump them while I'm bumping or adjusting other things.

Also it's fun to solve problems on my own.

About

Check GHA For Dependency Updates

Resources

Contributing

Stars

1 star

Watchers

1 watching

Forks

Releases

Sponsor this project

Contributors

Languages

Generated from sco1/py-template