Is this GitHub Action safe for your workflow?
Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.
Answeringour last check, 2026-09-28
1 of 1checks answered this week
22 msmedian answer time
$0.005listed price per call
$0.005price it asked us
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
GET https://aayatai.com/github/action
| Category | Image and media |
|---|---|
| Provider host | aayatai.com |
| Networks | eip155:137, eip155:42161, eip155:8453, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-09-28 | valid payment request | 402 | $0.005 | 22 ms |
Example input (from the provider)
{
"method": "GET",
"queryParams": {
"uses": "tj-actions/changed-files@v45.0.7"
},
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"properties": {
"uses": {
"description": "The action reference, e.g. actions/checkout@v4 or owner/repo/sub@<40-char sha>.",
"maxLength": 250,
"minLength": 5,
"type": "string"
}
},
"required": [
"uses"
],
"type": "object"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"properties": {
"action": {
"type": "string"
},
"advisories": {
"description": "OSV advisories for the action with affectsThisRef: yes / maybe / no / unknown.",
"items": {
"type": "object"
},
"type": "array"
},
"checkedAt": {
"type": "string"
},
"flags": {
"items": {
"type": "object"
},
"type": "array"
},
"pin": {
"enum": [
"sha",
"version-tag",
"major-tag",
"branch",
"other"
],
"type": "string"
},
"publisher": {
"enum": [
"well-known",
"third-party"
],
"type": "string"
},
"ref": {
"type": "string"
},
"repository": {
"type": [
"object",
"null"
]
},
"runtime": {
"type": [
"object",
"null"
]
},
"score": {
"type": "integer"
},
"sources": {
"items": {
"type": "string"
},
"type": "array"
},
"verdict": {
"enum": [
"ok",
"caution",
"avoid"
],
"type": "string"
}
},
"required": [
"action",
"ref",
"pin",
"verdict",
"score",
"flags",
"advisories"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}