Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Feature: warn when workflow YAML validates but would fail at runtime (schema vs runner gap)

Open
#611 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
github-actions, typescript
Domain
ci-cd, devtools

Research direction

Start by tracing the existing workflow YAML schema-validation entry point and the authenticated session already used for the API tree. Review how action.yml files and workflow triggers are resolved, then determine how the four opt-in runtime checks and workflow-file-hash cache fit alongside validation. Done means dismissible Information diagnostics run on open and save without blocking saves.

Written by the indexing model from the issue text.

Description

Summary

Extension validates workflow YAML against the schema, but many mistakes only surface after git push triggers a runner:

  • runs-on: referencing a self-hosted label that has no online runner
  • uses: owner/repo@ref where ref no longer resolves (deleted tag/branch, moved SHA)
  • secrets: inherit on a reusable workflow whose caller does not actually inherit
  • permissions: narrower than what a step needs (e.g. contents: read + a step that pushes)
  • if: expression referencing a context that is empty for the trigger (e.g. github.event.pull_request.* on push)

Each case validates green locally, then burns a runner minute and a red X on the PR.

Proposal

A "runtime-plausibility" pass, opt-in (github-actions.runtimeChecks.enabled), that runs alongside schema validation and surfaces Information-level diagnostics for:

  1. Unresolvable uses: refs (HEAD probe via the authenticated session already used for the API tree)
  2. runs-on: labels not present in the repo's runner list
  3. permissions: narrower than the union of permissions declared by any resolvable action's action.yml
  4. Context references that are empty for the declared on: triggers

None block save; all are dismissible. Runs on open + on save, cached by workflow-file hash.

Why not act / nektos

act runs the whole workflow in Docker; this is a static, seconds-scale lint. Complementary, not overlapping.

Related
  • #593 (commit-pinned actions reported unresolved) - same "static analysis of uses:" surface
  • #609 (false-positive missing-required-inputs) - related schema-vs-runtime gap in the other direction
Dominant language
TypeScript
Stars
661
Forks
214
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/vscode-github-actions

All issues in github/vscode-github-actions

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.