GitHub Actions Deploy Risk Audit

👤 daniellummis 📦 v1.0.0 ⭐ 4.4 ⬇️ 732 下載
🔒 IT運維與安全 免費

📖 技能介紹


name: github-actions-deploy-risk-audit description: Audit deployment workflow risk from GitHub Actions runs by scoring failure rate, unresolved failure streaks, and time since last successful deploy. version: 1.0.0 metadata: {"openclaw":{"requires":{"bins":["bash","python3"]}}}


GitHub Actions Deploy Risk Audit

Use this skill to rank deployment workflows that are currently risky to trust for production releases.

What this skill does

推薦訪問7w4.net獲取更多AI技能。

  • Reads GitHub Actions run JSON exports
  • Filters to deployment/release workflows (configurable regex)
  • Groups by repository + workflow + branch
  • Scores risk using:
  • failure rate
  • unresolved trailing failure streak
  • days since last successful run
  • Flags warning/critical groups based on configurable score thresholds
  • Emits text or JSON output for CI dashboards and release gates

Inputs

Optional: - RUN_GLOB (default: artifacts/github-actions/*.json) - TOP_N (default: 20) - OUTPUT_FORMAT (text or json, default: text) - MIN_RUNS (default: 2) - DEPLOY_WORKFLOW_MATCH (default: (?i)(deploy|release|ship|production)) - BRANCH_MATCH (regex, optional) - BRANCH_EXCLUDE (regex, optional) - REPO_MATCH (regex, optional) - REPO_EXCLUDE (regex, optional) - FAIL_WARN_PERCENT (default: 20) - FAIL_CRITICAL_PERCENT (default: 40) - STALE_SUCCESS_DAYS (default: 7) - WARN_SCORE (default: 35) - CRITICAL_SCORE (default: 60) - FAIL_ON_CRITICAL (0 or 1, default: 0)

Collect run JSON

gh run view <run-id> --json databaseId,workflowName,event,conclusion,headBranch,headSha,createdAt,updatedAt,startedAt,url,repository \
  > artifacts/github-actions/run-<run-id>.json

Run

Text report:

RUN_GLOB='artifacts/github-actions/*.json' \
DEPLOY_WORKFLOW_MATCH='(?i)(deploy|release)' \
MIN_RUNS=3 \
bash skills/github-actions-deploy-risk-audit/scripts/deploy-risk-audit.sh

JSON output with fail gate:

RUN_GLOB='artifacts/github-actions/*.json' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-deploy-risk-audit/scripts/deploy-risk-audit.sh

Run with bundled fixtures:

RUN_GLOB='skills/github-actions-deploy-risk-audit/fixtures/*.json' \
bash skills/github-actions-deploy-risk-audit/scripts/deploy-risk-audit.sh

Output contract

  • Exit 0 in report mode (default)
  • Exit 1 when FAIL_ON_CRITICAL=1 and one or more groups are critical
  • Text mode prints summary + ranked deploy risk groups
  • JSON mode prints summary + scored groups + critical group details

🤖 AI 評測

這個 Skill 功能實用,能有效識別高風險的部署工作流。配置靈活,支援多種過濾條件,輸出清晰,錯誤提示友好。主要問題是缺少測試覆蓋,可靠性存疑,且文件中提到的測試資料實際上不存在。總體質量中等偏上,適合有技術背景的使用者使用,但建議等待補充測試後再用於生產環境。

📊 多維度評分

適應性4.5
規範性4.4
有效性4.5
可靠性4.4
可信度4.3

📁 包含檔案 (3 個)

📄 SKILL.md 2.5 KB
📄 _meta.json 151 B
📄 scripts/deploy-risk-audit.sh 12 KB