Product

Find GitHub Actions breakage before it turns into a release blocker

A local workflow scanner for deprecated artifact/cache actions, runner drift, Node runtime pressure, broad permissions, local actions, and fail-closed workflow YAML findings.

Start here

Run the free scanner and review its findings.

Run the free local scanner and inspect its JSON/HTML report. Check the documented scope and manual migration guidance.

  • Local workflow with no repo upload.
  • Source-linked findings and manual guidance; no automatic edits.
  • Manual-review findings stay visible instead of hidden.

Checkout is not listed yet.

Trust boundary

Scope and validation

  • Run on a branch and review the documented scope before applying changes.
  • The public repo is scanner-first and does not expose the full paid apply engine.
  • Examples establish only the cases shown. Run your own application tests before merging.

What this fixes

  • Deprecated actions/upload-artifact@v3 and actions/download-artifact@v3 references.
  • Retired actions/cache@v1 and actions/cache@v2 usage.
  • Runner label drift such as ubuntu-20.04 retirement and macos-latest migration risk.
  • Node runtime and temporary Node 20 opt-out findings for Actions.
  • Missing or broad GITHUB_TOKEN permissions blocks.
  • Invalid workflow YAML and local/composite action inventory that should not be guessed through.

What this proof includes

  • Local scanner with JSON and HTML report output.
  • Source-linked manual guidance; no rule is currently eligible for automatic edits.
  • Rule-pack version, source-backed findings, deadlines, fixability classification, and confidence scoring.
  • Fail-closed findings for workflow shapes the scanner cannot patch safely.

Example before/after

See the deliverable shape before it is listed.

Illustrative output format: sample counts and validation results below are not a run on your repository. Use the linked proof artifacts for recorded evidence. You can also make changes manually using the free report and migration guides.

Local command

git clone https://github.com/zippertools/sqlalchemy-14-to-20-codemod
python -m pip install -e sqlalchemy-14-to-20-codemod/products/actions-upgrade-guard
python -m actions_upgrade_guard.cli path/to/repo --report actions-upgrade-report.json --html-report actions-upgrade-report.html

Use a local checkout. No GitHub token, hosted scan, or source upload is required.

Sample report

Actions Upgrade Guard Report
status: manual_review_required
rule_pack_version: 2026.09.26
scanned_files: .github/workflows/build.yml
blocking_findings: 3
patches: 0

Before/after diff preview

No safe patch generated. Review platform, runner, shared artifact names, hidden files, and download compatibility using each finding's source.

The free local tool produces findings and manual alternatives for the documented subset; no upgrades are auto-applied. No paid Action Guard package is currently offered.

PatternBehavior
artifact/cache action deprecationsmanual compatibility review
runner label driftfinding with deadline/source
permissions riskmanual review
invalid YAMLblocked/fail closed

Apply output

preview output
files_changed: 0
patches_generated: 0
autofix_findings: none
manual_review_findings: AUG001, AUG002

Validation summary

validation summary
pytest products/actions-upgrade-guard ... passed
ruff check products/actions-upgrade-guard ... passed
mypy src tests ... passed
wheel build ... passed

Final manager summary

final manager summary
Blocking workflow findings: 3
No safe automatic patches; review upstream migration guidance.
Manual review: runner labels and GITHUB_TOKEN permissions

Use this if

  • Platform engineers responsible for keeping many GitHub Actions workflows current.
  • DevOps leads cleaning up artifact, cache, runner, Node runtime, and permission risks before they block releases.
  • Repo owners who need a manager-readable Actions risk report without giving a hosted service repository access.

Public proof and fit signals

  • Public proof shows legacy artifact and cache references with explicit manual review and no automatic edits.
  • Runner, Node runtime, permission, local-action, and invalid-YAML cases stay visible as findings instead of guessed fixes.
  • The scanner runs locally with no GitHub token, source upload, or automatic workflow edits.

Do not use this if

  • Teams looking for hosted monitoring or automatic GitHub account access.
  • Generated workflows where the generated YAML is not checked into the repo.
  • Security hardening beyond the documented workflow-upgrade rules.

How delivery works

  • Open the public README and run the scanner against a local checkout.
  • Review actions-upgrade-report.json and actions-upgrade-report.html.
  • Review findings against the upstream documentation, make changes on a branch, and run your CI.
  • No paid Action Guard package is currently offered.

Refund/support note

No Action Guard purchase is available yet. Use the proof page and public scanner for fit questions; do not send private workflow files through support.

Support: support@zippertools.org

Next step

Action Guard is free

Use the free scanner and inspect the reproducible examples. No paid Action Guard package is currently offered.

Checkout not listed yet

Explore the details

No checkout is listed for this proof page yet.

Related fixes

Exact-problem guides for this product