Repository navigation
[lockfile-stats] Lockfile Statistics Report — 2026-10-02 (302 workflows) #65096
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-03T20:30:02.722Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics Report — 2026-10-02
302 compiled lockfiles analyzed (
0skipped/malformed) · 45.4 MB total · avg 153.8 KB/file (min 90.9 KB, max 247.1 KB)File size distribution
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(213),workflow_dispatchonly (37),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Most common cron cadence:
0 0 */2 * *(every 2 days) — 45 workflows. Long tail of unique daily/weekday crons beyond that.Safe outputs analysis
Discussion category breakdown (92 workflows producing discussions):
audits79,announcements5,artifacts2,dev2,research2,general1,daily-news1.Detection self-check:
create_discussion_workflows=92,discussion_category_detected=92 (100%), unresolved=0, regex-fallback used=0,safe_outputs_config_missing=0 — full JSON-based extraction succeeded for every discussion-producing workflow.Structural characteristics
Timeout distribution (job-level, minutes)
Permission patterns (agent job only; top-level
permissions: {}carries no signal)permissions_unknown=0 — every lockfile's agent job permissions resolved cleanly. The agent job is read-only almost everywhere; writes are delegated to a separate safe-outputs applier job.Union-of-all-jobs permissions (effective write capability per workflow)
union_any_write_count= 302/302 (100%) — every workflow has at least one job (the safe-outputs applier) capable of a write, confirming the read-only-agent / write-only-applier security pattern holds repo-wide.Engine distribution
agent_id)engine_unknown=0 — every lockfile'sgh-aw-metadataresolved anagent_id.Tool & MCP patterns
mcp_fallback_used_count=0 — all server/tool usage came from thegh-aw-manifestJSON, no legacy scraping needed.Interesting findings
writeonissues/pull-requests/discussions(all read/none), yet 100% of workflows have some job with write access — the safe-outputs applier-job pattern is applied without exception across all 302 lockfiles.missing_data/missing_tool/noop/report_incompleteappear in 296/302 (98.0%) lockfiles; 6 lockfiles lack the standard contract, likely older or specialized workflows worth auditing.create_discussionworkflows resolved a category via direct JSON parsing, with zero fallback-regex or unresolved cases —auditsaccounts for 86% (79/92) of discussion output.workflow_dispatchfor manual re-runs — near-total adoption of the schedule+dispatch pairing.copilotandcodextogether power 66.6% of workflows (201/302), withclaudeat 18.5%; the remaining 9 engines are long-tail, each under 1.3%.Historical trends (vs. 2026-10-01)
Growth is incremental — one new lockfile added, attributable to the
copilotengine, with no shift in discussion-category or safe-output adoption.Recommendations
missing_data/missing_tool/noop/report_incompletesafe-output scaffolding for consistency with the rest of the fleet.0 0 */2 * *) would reduce scheduling sprawl.engine_unknown,permissions_unknown, andsafe_outputs_config_missingare all 0; the extraction pipeline is healthy.Methodology: single-script compact JSON analysis (
lockfile_stats_v4.py, cached incache-memory), parsinggh-aw-metadata/gh-aw-manifestcomments andGH_AW_SAFE_OUTPUTS_CONFIGenv JSON across all.github/workflows/*.lock.ymlfiles in one pass.All reactions