81trust / 100

Github Action

by Aayat AI in Developer tools

x402 APIPassing, checked 3 h ago

Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.

GET https://aayatai.com/github/action

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
47 ms typical, 47 ms slowest 5%
Last check
3 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Faayatai.com%2Fgithub%2Faction
const res = await pay("https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7");
console.log(await res.json());

Example input

{
  "uses": "tj-actions/[email protected]"
}

Example output

{
  "action": "tj-actions/changed-files",
  "advisories": [
    {
      "affectsThisRef": "yes",
      "aliases": [
        "CVE-2025-30066"
      ],
      "fixedIn": [
        "46.0.1"
      ],
      "id": "GHSA-mrrh-fwg8-r2c3",
      "published": "2025-03-15T00:00:00Z",
      "severity": "high",
      "summary": "tj-actions/changed-files has a malicious commit",
      "url": "https://osv.dev/vulnerability/GHSA-mrrh-fwg8-r2c3"
    }
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "flags": [
    {
      "code": "vulnerable",
      "level": "danger",
      "message": "1 advisory(ies) affect v45.0.7: tj-actions/changed-files has a malicious commit. Upgrade to 46.0.1."
    }
  ],
  "pin": "version-tag",
  "publisher": "third-party",
  "ref": "v45.0.7",
  "repository": {
    "archived": false,
    "lastPushAt": "2026-09-20T00:00:00Z",
    "latestRelease": {
      "publishedAt": "2026-09-01T00:00:00Z",
      "tag": "v47.0.0"
    },
    "stars": 2600,
    "url": "https://github.com/tj-actions/changed-files",
    "verdict": "healthy"
  },
  "runtime": {
    "actionYml": "https://raw.githubusercontent.com/tj-actions/changed-files/v45.0.7/action.yml",
    "image": null,
    "nestedUses": [],
    "using": "composite"
  },
  "score": 30,
  "sources": [
    "OSV.dev (GitHub Actions advisories)",
    "action.yml via raw.githubusercontent.com",
    "GitHub REST"
  ],
  "verdict": "avoid"
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
3 h agoPassed40247 ms$0.005