Github Action
Description
The github/action crawler looks recursively for workflow files and Composite Actions, then tries to update every action reference found in them.
It scans two kinds of file:
Workflows - files matching
.yamlor.ymllocated directly inside aworkflowsdirectory whose parent is.github,.gitea, or.forgejo.Composite Actions - files named
action.yamloraction.yml, in any directory.
Despite its name, the crawler is not GitHub-only: .gitea/workflows and .forgejo/workflows are scanned as well, and the provider is detected from each action reference.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a github/action crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Note | The crawler key is github/action. The alias gitea/action maps to the same implementation, but it is not part of the default crawlers, so it only runs when explicitly declared. |
Generated manifests
Action references are updated in place with a yaml target. The source depends on the provider and on the shape of the reference:
| Reference | Sources used |
|---|---|
| |
| |
| |
| Skipped - local actions have no upstream to track. |
Digest pinning
digest defaults to true, so generated manifests pin references to an immutable digest and keep the human-readable version as a trailing comment:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1Set digest: false to write the tag or branch directly instead.
Important | Digest pinning is only implemented for GitHub Actions and Docker image references. Gitea and Forgejo actions are always updated to a tag or branch. |
Authentication
Discovery queries the provider’s API, so unauthenticated runs are rate limited and private repositories are invisible.
Tokens are resolved per hostname, from credentials, from a GitHub App configuration, or from the environment:
GitHub:
UPDATECLI_GITHUB_TOKEN, thenGITHUB_TOKENGitea and Forgejo:
UPDATECLI_GITEA_TOKEN, thenGITEA_TOKEN
gitea.com, codeberg.org, and code.forgejo.org are recognised as Gitea automatically. Any other unknown hostname falls back to GitHub.
Use credentialsdocker to authenticate against a private registry when resolving docker:// references.
Limitations
filesmatches the file name only, not a path. Patterns such as.github/workflows/.yamlmatch nothing; use.yamlorci.yaml. The directory is constrained separately, to.github,.gitea, or.forgejoworkflow directories.actionsfilters Composite Actions by the name of the directory containingaction.yaml, not by the file path.Workflow files that are not directly inside a
workflowsdirectory are ignored.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| actions | array | “actions” defines the composite action name patterns the crawler searches for. default: remark:
| |
| age | object | “age” defines the minimum or maximum age of a release, tag, or branch to be considered valid. It is the “dependency cooldown” setting: setting “minimum” keeps Updatecli from suggesting a version that has just been published. default: empty, no age filtering. remark:
example: | |
| maximum | string | “maximum” defines the maximum age a release may have to be considered. remark:
example:
| |
| minimum | string | “minimum” defines the minimum age a release must have to be considered. remark:
example:
| |
| credentials | object | “credentials” defines the credentials used to authenticate with each git provider, keyed by git provider domain. remark:
example: | |
| app | object | ||
| clientid | string | “clientid” defines the GitHub App client ID. | |
| expirationtime | string | “expirationtime” defines the lifetime of the GitHub App token, in seconds. default: 3600 remark:
| |
| installationid | string | “installationid” defines the GitHub App installation ID. remark:
| |
| privatekey | string | “privatekey” defines the PEM encoded private key of the GitHub App. remark:
| |
| privatekeypath | string | “privatekeypath” defines the path to a file holding the PEM encoded private key of the GitHub App. remark:
example:
| |
| kind | string | ||
| token | string | ||
| credentialsdocker | object | “credentialsdocker” defines the registry credentials used for Docker images, keyed by registry host without scheme. remark:
example: | |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| digest | boolean | “digest” defines whether the generated manifests pin the digest instead of the branch or tag. default: true remark:
| |
| files | array | “files” defines the workflow file name patterns the crawler searches for. default: remark:
| |
| ignore | array | “ignore” defines rules to exclude matching actions or Docker images from the autodiscovery. remark:
| |
| actions | object | “actions” defines the actions and Docker images to match, keyed by name. remark:
| |
| path | string | “path” defines a workflow or composite action file path pattern. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching actions or Docker images. remark:
| |
| actions | object | “actions” defines the actions and Docker images to match, keyed by name. remark:
| |
| path | string | “path” defines a workflow or composite action file path pattern. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for workflow files and composite actions. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default:
remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Note | Each entry of credentials is keyed by the git provider hostname, and accepts kind (github, gitea, or forgejo) along with a token or a GitHub App configuration. |
Example
Basic Example
# updatecli.d/default.yaml
name: "githubaction autodiscovery"
scms:
default:
kind: git
spec:
url: https://github.com/updatecli/updatecli.git
branch: "main"
autodiscovery:
scmid: default
crawlers:
github/action:
digest: true
rootdir: ".github"
Multiple providers
# updatecli.d/github-action-providers.yaml
autodiscovery:
crawlers:
github/action:
# Pin to a tag or branch rather than a digest
digest: false
credentials:
"github.com":
kind: github
token: '{{ requiredEnv "GITHUB_TOKEN" }}'
"codeberg.org":
kind: forgejo
token: '{{ requiredEnv "FORGEJO_TOKEN" }}'
versionfilter:
kind: semver
pattern: minorImportant | Crawler settings are declared directly under the crawler key. An extra spec: level is accepted by the parser but silently ignored, leaving every setting at its default. |