{"_id":"github-actionlint","_rev":"2-0416b9967ba0337934ac38ad1b83fa6d","name":"github-actionlint","dist-tags":{"latest":"1.7.12"},"versions":{"1.7.11":{"name":"github-actionlint","version":"1.7.11","keywords":["actionlint","github-actionlint","github-actions","workflow","linter","ci"],"license":"MIT","_id":"github-actionlint@1.7.11","maintainers":[{"name":"judeallred","email":"blinkymach12@gmail.com"}],"homepage":"https://github.com/judeallred/github-actionlint#readme","bugs":{"url":"https://github.com/judeallred/github-actionlint/issues"},"bin":{"github-actionlint":"dist/bin/actionlint.js"},"dist":{"shasum":"c3e444df608f437d421e6a67d7bf7f7449c9463f","tarball":"https://registry.npmjs.org/github-actionlint/-/github-actionlint-1.7.11.tgz","fileCount":21,"integrity":"sha512-dvMaSooYn/LXCVvG58USvjaHkShofJpu43wRoMTVMnq/pl3w3osRgRA7wtnHlJAnoWiofkimMmfll3yDuSkDCA==","signatures":[{"sig":"MEQCIBmTS8eLj0ePaPVDCCxU2APAbEkBCiPdxOu7jnQN0VRpAiBvlhmFjeonb1qsZDm+wtjGLQdEwoIoUXvLWspJvvU3fg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31982},"main":"dist/lib/index.js","types":"dist/lib/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"1bf52471b21926310c96bd62a2aba919671aacfb","scripts":{"lint":"eslint lib bin test *.config.*","test":"tsx test/run-tests.ts","build":"tsc","format":"prettier --write .","lint:fix":"eslint . --fix","test:parity":"tsx test/parity-test.ts","format:check":"prettier --check .","lint:workflows":"node dist/bin/actionlint.js .github/workflows/*.yaml","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"judeallred","email":"blinkymach12@gmail.com"},"repository":{"url":"git+https://github.com/judeallred/github-actionlint.git","type":"git"},"_npmVersion":"11.7.0","description":"Run rhysd/actionlint from Node.js - downloads the official binary from GitHub Releases","directories":{},"_nodeVersion":"24.11.1","dependencies":{"tar":"^7.4.0","adm-zip":"^0.5.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.0.0","eslint":"^9.0.0","prettier":"^3.0.0","@eslint/js":"^9.0.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/adm-zip":"^0.5.8","typescript-eslint":"^8.0.0","eslint-config-prettier":"^9.0.0"},"_npmOperationalInternal":{"tmp":"tmp/github-actionlint_1.7.11_1774019351879_0.17125009887414433","host":"s3://npm-registry-packages-npm-production"}},"1.7.12":{"name":"github-actionlint","version":"1.7.12","description":"Run rhysd/actionlint from Node.js - downloads the official binary from GitHub Releases","license":"MIT","repository":{"type":"git","url":"git+https://github.com/judeallred/github-actionlint.git"},"bugs":{"url":"https://github.com/judeallred/github-actionlint/issues"},"homepage":"https://github.com/judeallred/github-actionlint#readme","keywords":["actionlint","github-actionlint","github-actions","workflow","linter","ci"],"bin":{"github-actionlint":"dist/bin/actionlint.js"},"main":"dist/lib/index.js","types":"dist/lib/index.d.ts","scripts":{"build":"tsc","test":"tsx test/run-tests.ts","test:parity":"tsx test/parity-test.ts","lint":"eslint lib bin test *.config.*","lint:fix":"eslint . --fix","format":"prettier --write .","format:check":"prettier --check .","lint:workflows":"node dist/bin/actionlint.js .github/workflows/*.yaml","prepublishOnly":"npm run build && npm test"},"engines":{"node":">=18.0.0"},"dependencies":{"adm-zip":"^0.5.16","tar":"^7.4.0"},"devDependencies":{"@eslint/js":"^9.0.0","@types/adm-zip":"^0.5.8","@types/node":"^22.0.0","eslint":"^9.0.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.0","tsx":"^4.0.0","typescript":"^5.0.0","typescript-eslint":"^8.0.0"},"gitHead":"967c492e2c7028917aaabe0993cb163013b8c3ac","_id":"github-actionlint@1.7.12","_nodeVersion":"22.22.2","_npmVersion":"11.12.1","dist":{"integrity":"sha512-kSVz5clt9voatp2Tdh1BETKNooT358/nPChYseaDC4M6f9Hc/sBRMbhagx2FTu2F/WHzDoxlNPh2EqwBngTYQg==","shasum":"55d60ee9d819cb871d05cda0dad40331beb3cf2b","tarball":"https://registry.npmjs.org/github-actionlint/-/github-actionlint-1.7.12.tgz","fileCount":21,"unpackedSize":36914,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/github-actionlint@1.7.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHBjO/iynKwNBXbCaDx+aKj73kxxGY0+2yPRQX7dqwZJAiBVkKtb5l1aodcR2h6QpbfKdkM2MNh/K+PuTiNsKfxY8g=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:fe4c84ef-cb68-441e-83d5-84f1bd30c7aa"}},"directories":{},"maintainers":[{"name":"judeallred","email":"blinkymach12@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/github-actionlint_1.7.12_1776101235513_0.08693664428230519"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-20T15:09:11.804Z","modified":"2026-04-13T17:27:16.325Z","1.7.11":"2026-03-20T15:09:12.055Z","1.7.12":"2026-04-13T17:27:15.721Z"},"bugs":{"url":"https://github.com/judeallred/github-actionlint/issues"},"license":"MIT","homepage":"https://github.com/judeallred/github-actionlint#readme","keywords":["actionlint","github-actionlint","github-actions","workflow","linter","ci"],"repository":{"type":"git","url":"git+https://github.com/judeallred/github-actionlint.git"},"description":"Run rhysd/actionlint from Node.js - downloads the official binary from GitHub Releases","maintainers":[{"name":"judeallred","email":"blinkymach12@gmail.com"}],"readme":"# github-actionlint\n\n[![npm](https://img.shields.io/npm/v/github-actionlint)](https://www.npmjs.com/package/github-actionlint)\n\nRun [actionlint](https://github.com/rhysd/actionlint)—the linter for GitHub Actions workflows—from your Node.js project. No separate install step for a binary: add a dev dependency, wire a script, and catch workflow mistakes before they land on `main`.\n\n---\n\n## Why this exists\n\nGitHub Actions YAML looks simple until it isn’t: expression contexts, reusable workflows, `secrets` vs `env`, shell injection in `run:` blocks, and copy-pasted paths that only break in CI. [actionlint](https://github.com/rhysd/actionlint) was built to lint those workflows the way ESLint lints JavaScript.\n\n**Motivation for this package:** many teams already standardize on **npm** for developer tooling. Installing actionlint through npm means:\n\n- **One toolchain**—`npm install` / `pnpm add` / `yarn add` alongside your other devDependencies.\n- **No manual binary management** on each machine or CI image; the first run downloads the official release for your OS/arch and caches it under `~/.github-actionlint`.\n- **Pinning**—lock the linter version in `package-lock.json` (or equivalent) so everyone runs the same rules.\n\nUse it locally before you push, in **pre-commit** hooks, and in **CI** so broken workflows fail fast.\n\n---\n\n## Credits & upstream documentation\n\n**github-actionlint** is not a reimplementation: it downloads and runs the official **actionlint** binary from [rhysd/actionlint](https://github.com/rhysd/actionlint). All workflow checks, flags, and behavior come from that project.\n\nFor authoritative details—every CLI flag, [configuration](https://github.com/rhysd/actionlint/blob/main/docs/config.md), ignore rules, and editor integrations—use the upstream docs, especially:\n\n- **[Usage](https://github.com/rhysd/actionlint/blob/main/docs/usage.md)** — command-line options (including `-shellcheck` / `-pyflakes`)\n- **[Checks](https://github.com/rhysd/actionlint/blob/main/docs/checks.md)** — what actionlint validates and how optional tools integrate\n\n---\n\n## Optional integrations: shellcheck and pyflakes\n\nactionlint can delegate to external linters for scripts inside `run:` steps. Per the [shellcheck integration](https://github.com/rhysd/actionlint/blob/main/docs/checks.md#check-shellcheck-integ) and [pyflakes integration](https://github.com/rhysd/actionlint/blob/main/docs/checks.md#check-pyflakes-integ) sections of the upstream **checks** documentation:\n\n- **By default**, actionlint looks for `shellcheck` and `pyflakes` on your **`PATH`** and uses each one **only if it is found**. If `pyflakes` (or `shellcheck`) is not installed or not on your path, **that integration is skipped**—actionlint still runs; you simply do not get those extra `run:`-script checks from the missing tool.\n- **GitHub Actions:** [shellcheck](https://github.com/koalaman/shellcheck) is **pre-installed on GitHub-hosted runners** (e.g. `ubuntu-latest`, `macos-latest`, `windows-latest`), so shellcheck-backed checks for `run:` scripts work in CI without extra setup—see the [runner image software lists](https://github.com/actions/runner-images). **pyflakes** is not included by default; install it in the job (e.g. `pip install pyflakes`) if you want those checks in Actions.\n- To point at a specific executable, use `-shellcheck=/path/to/shellcheck` or `-pyflakes=/path/to/pyflakes`.\n- To turn an integration off explicitly (and avoid spawning those processes), use `-shellcheck=` or `-pyflakes=` with an **empty** value—see [Ignore some errors](https://github.com/rhysd/actionlint/blob/main/docs/usage.md#ignore-some-errors) in the upstream usage guide.\n\nOn a **local** machine you may need to install [shellcheck](https://github.com/koalaman/shellcheck) and/or [pyflakes](https://github.com/PyCQA/pyflakes) (e.g. `pip install pyflakes`) if they are not already on your `PATH`.\n\n---\n\n## Install\n\n```bash\nnpm install --save-dev github-actionlint\n```\n\n---\n\n## Use it in practice\n\n### Add a script to `package.json`\n\nMost projects add a dedicated script so “check my workflows” is one command:\n\n```json\n{\n  \"scripts\": {\n    \"check:actions\": \"github-actionlint .github/workflows/\"\n  }\n}\n```\n\nThen:\n\n```bash\nnpm run check:actions\n```\n\nYou can combine it with other checks:\n\n```json\n{\n  \"scripts\": {\n    \"check\": \"npm run check:actions && npm run lint && npm run test\",\n    \"check:actions\": \"github-actionlint .github/workflows/\"\n  }\n}\n```\n\n### CLI examples\n\n```bash\n# Default: lint workflow files under .github/workflows/\nnpx github-actionlint .github/workflows/\n\n# More detail\nnpx github-actionlint -color -verbose .github/workflows/\n\n# Match what you run in CI (paths depend on your repo layout)\nnpx github-actionlint .github/workflows/*.yaml\n```\n\n### Programmatic API\n\n```js\nconst { actionlint } = require(\"github-actionlint\");\n\nconst result = await actionlint({\n  args: [\".github/workflows/\", \"-color\"],\n});\nconsole.log(result.stdout.toString());\nconsole.log(result.stderr.toString());\nprocess.exit(result.code);\n```\n\n---\n\n## Environment variables\n\n| Variable               | Description                                   |\n| ---------------------- | --------------------------------------------- |\n| `ACTIONLINT_BIN`       | Path to actionlint binary (skip download)     |\n| `ACTIONLINT_RELEASE`   | actionlint version (default: package version) |\n| `ACTIONLINT_CACHE_DIR` | Cache directory for downloaded binary         |\n| `GITHUB_TOKEN`         | GitHub token for API rate limits (optional)   |\n\n---\n\n## Supported platforms\n\n- **macOS**: x64, arm64\n- **Linux**: x64, arm64, 386, arm\n- **Windows**: x64, arm64\n- **FreeBSD**: 386, amd64\n\n---\n\n## Versioning\n\nThis package **tracks [rhysd/actionlint](https://github.com/rhysd/actionlint) releases**: the npm version matches the actionlint version it bundles. When upstream ships a new release, **github-actionlint** publishes a matching version so you stay aligned with the official linter.\n\n---\n\n## Releasing & maintenance\n\nMaintainers: see [RELEASING.md](./RELEASING.md) for automated upstream sync, GitHub Releases, and npm publishing (including Trusted Publishers / OIDC).\n\n## License\n\nMIT\n","readmeFilename":"README.md"}