Public proof

GitHub Actions Upgrade Guard proof artifacts

Public proof artifacts for GitHub Actions Upgrade Guard, including before workflow, command, generated report, manual alternatives, and fail-closed findings.

Trust boundary

Scope and validation

  • Run on a branch and review the documented scope before applying changes.
  • The public repo is scanner-first and does not expose the full paid apply engine.
  • Examples establish only the cases shown. Run your own application tests before merging.

Before workflow

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/cache@v2
      - uses: actions/upload-artifact@v3
      - uses: actions/download-artifact@v3

Command

git clone https://github.com/zippertools/sqlalchemy-14-to-20-codemod
python -m pip install -e sqlalchemy-14-to-20-codemod/products/actions-upgrade-guard
python -m actions_upgrade_guard.cli . --report actions-upgrade-report.json --html-report actions-upgrade-report.html

The scanner runs locally and writes JSON plus HTML reports without a GitHub token.

Buyer-readable report excerpt

status: manual_review_required
rule_pack_version: 2026.09.26
scanned_files: .github/workflows/build.yml
blocking_findings: 3
autofix_findings: none
manual_review: AUG001, AUG002; informational: AUG006, AUG008

Patch preview

No safe patch generated. Review platform, runner, shared artifact names, hidden files, and download compatibility using each finding's source.

Fail-closed findings

  • Missing or broad permissions are reported for review instead of rewritten blindly.
  • Floating runner labels are source-linked findings, not automatic edits.
  • Invalid YAML exits as a blocked finding instead of crashing or guessing.

Do not buy this if

  • Teams looking for hosted monitoring or automatic GitHub account access.
  • Generated workflows where the generated YAML is not checked into the repo.
  • Security hardening beyond the documented workflow-upgrade rules.

Why this is not just actionlint

Action Guard is not trying to replace syntax linting. It is a deadline-readiness report: source-backed deprecation rules, fixability classification, manual migration guidance, and a manager-readable risk surface for workflow changes that can break releases.