81trust / 100
Github Action
by Aayat AI in Developer tools
x402 APIPassing, checked 3 h ago
Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.
GET https://aayatai.com/github/action
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 47 ms typical, 47 ms slowest 5%
- Last check
- 3 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Faayatai.com%2Fgithub%2Faction
const res = await pay("https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7");
console.log(await res.json());Example input
{
"uses": "tj-actions/[email protected]"
}Example output
{
"action": "tj-actions/changed-files",
"advisories": [
{
"affectsThisRef": "yes",
"aliases": [
"CVE-2025-30066"
],
"fixedIn": [
"46.0.1"
],
"id": "GHSA-mrrh-fwg8-r2c3",
"published": "2025-03-15T00:00:00Z",
"severity": "high",
"summary": "tj-actions/changed-files has a malicious commit",
"url": "https://osv.dev/vulnerability/GHSA-mrrh-fwg8-r2c3"
}
],
"checkedAt": "2026-09-28T12:00:00.000Z",
"flags": [
{
"code": "vulnerable",
"level": "danger",
"message": "1 advisory(ies) affect v45.0.7: tj-actions/changed-files has a malicious commit. Upgrade to 46.0.1."
}
],
"pin": "version-tag",
"publisher": "third-party",
"ref": "v45.0.7",
"repository": {
"archived": false,
"lastPushAt": "2026-09-20T00:00:00Z",
"latestRelease": {
"publishedAt": "2026-09-01T00:00:00Z",
"tag": "v47.0.0"
},
"stars": 2600,
"url": "https://github.com/tj-actions/changed-files",
"verdict": "healthy"
},
"runtime": {
"actionYml": "https://raw.githubusercontent.com/tj-actions/changed-files/v45.0.7/action.yml",
"image": null,
"nestedUses": [],
"using": "composite"
},
"score": 30,
"sources": [
"OSV.dev (GitHub Actions advisories)",
"action.yml via raw.githubusercontent.com",
"GitHub REST"
],
"verdict": "avoid"
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 3 h ago | Passed | 402 | 47 ms | $0.005 |