{"slug":"aayatai-com-github-action-541fa6","title":"Is this GitHub Action safe for your workflow?","host":"aayatai.com","method":"GET","resource":"https://aayatai.com/github/action","category":"image","description":"Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. ","price_listed":0.005,"price_asked":0.005,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":22,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:137","eip155:42161","eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"uses":"tj-actions/changed-files@v45.0.7"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"uses":{"description":"The action reference, e.g. actions/checkout@v4 or owner/repo/sub@<40-char sha>.","maxLength":250,"minLength":5,"type":"string"}},"required":["uses"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"action":{"type":"string"},"advisories":{"description":"OSV advisories for the action with affectsThisRef: yes / maybe / no / unknown.","items":{"type":"object"},"type":"array"},"checkedAt":{"type":"string"},"flags":{"items":{"type":"object"},"type":"array"},"pin":{"enum":["sha","version-tag","major-tag","branch","other"],"type":"string"},"publisher":{"enum":["well-known","third-party"],"type":"string"},"ref":{"type":"string"},"repository":{"type":["object","null"]},"runtime":{"type":["object","null"]},"score":{"type":"integer"},"sources":{"items":{"type":"string"},"type":"array"},"verdict":{"enum":["ok","caution","avoid"],"type":"string"}},"required":["action","ref","pin","verdict","score","flags","advisories"],"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-28","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.005,"price_match":true,"latency_ms":22,"error":null}],"description_full":"Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.","last_updated":"2026-09-28T10:46:40.388Z","schemes":["exact"]}