{"slug":"api-zfinia-com-x402-v1-github-actions-workflow-audit-f3c89e","title":"Audit one GitHub Actions workflow against a contract the caller states","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/github-actions-workflow-audit","category":"code","description":"Audit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an ","price_listed":0.2,"price_asked":null,"state":"effects","state_label":"Not tested: has real-world effects","checks_7d":0,"answered_7d":0,"latency_ms_median":null,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"contract":{"require_concurrency":true,"require_explicit_permissions":true,"require_pinned_actions":true,"require_timeout":true},"workflow":"name: ci\non:\n  pull_request_target:\n    branches: [main]\njobs:\n  build:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n        with:\n          ref: ${{ github.event.pull_request.head.sha }}\n      - uses: some-vendor/deploy-action@v1\n      - name: publish\n        run: npm publish --token ${{ secrets.NPM_TOKEN }}\n      - name: label\n        run: echo \"${{ github.event.pull_request.title }}\"\n"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"contract":{"additionalProperties":false,"properties":{"require_concurrency":{"type":"boolean"},"require_explicit_permissions":{"type":"boolean"},"require_pinned_actions":{"type":"boolean"},"require_timeout":{"type":"boolean"},"trusted_action_owners":{"items":{"maxLength":64,"type":"string"},"maxItems":50,"minItems":1,"type":"array"}},"type":"object"},"workflow":{"maxLength":262144,"type":"string"}},"required":["workflow"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[],"description_full":"Audit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an action pinned to a mutable tag, a secret or author-controlled event field interpolated into a run command, an absent permissions block, and the trigger key read as a boolean.","last_updated":"2026-10-04T08:24:33.182Z","schemes":["exact"]}