Repository navigation
[lockfile-stats] Lockfile Statistics — 2026-10-03 (319 lockfiles, +17 vs prior snapshot) #65425
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #65664. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-10-03
Analysis of 319
.github/workflows/*.lock.ymlfiles (0 malformed/skipped), totaling 49,594,057 bytes (~47.3 MB). Methodology: single-script compact JSON analysis (lockfile_stats_v4.py, cached incache-memory/scripts/).Key metrics
workflow_dispatchpresentcreate_discussionworkflowsFile size distribution
Sizes cluster tightly: avg 155 KB with a 85.6–253.8 KB range (2.96x spread). No single lockfile dominates; the distribution looks like steady per-workflow boilerplate (safe-outputs scaffolding) plus variable per-workflow prompt/tooling content.
Trigger analysis
Trigger counts and top combinations
Top trigger combinations:
schedule+workflow_dispatch(216, 67.7%),workflow_dispatchonly (51, 16.0%),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Top cron cadence:
0 0 */2 * *(every 2 days) — 46 workflows, by far the most common schedule.Safe outputs analysis
Safe-output type counts (top 15 of 56 types)
Discussion categories (92
create_discussionworkflows, 100% category-detected, 0 fallback-parsed, 0 unresolved):Structural characteristics
Permission patterns (agent job only — top-level
permissions:{}carries no signal)Agent job permissions by scope
Union across all jobs (any job in the workflow granting the scope):
issues:writeappears in all 319 workflows (100%) — the safe-outputs dispatcher job universally requires issue-write scope.contentsis write in 210 (65.8%), read-only in 109.union_any_write_count= 319 (every workflow has at least one write-capable job).Engine distribution
(derived from
gh-aw-metadataagent_id; 0 unresolved)Tool & MCP patterns
MCP servers:
safeoutputs(319, 100%),github(192, 60.2%),agenticworkflows(44),serena(25),mcpscripts(25),tavily(5), long tail of 11 others at ≤4.mcp_fallback_used_count= 0 (manifest-based detection worked for every lockfile).Most-used tools:
github:get_commit/get_file_contents/etc. (184 each, the read-only baseline toolkit),safeoutputs:create_issue(164),github:get_me(159),safeoutputs:create_discussion(92).Interesting findings
0 0 */2 * *(every 2 days) alone accounts for 46 of 249 scheduled workflows (18.5%) — far ahead of any other cron pattern, suggesting a strong default convention rather than organic diversity.noop/missing_tool/missing_data/report_incompleteappear in 312/319 workflows (97.8%), up from 296/302 (98.0%) last snapshot — this contract is being adopted as a default, not an opt-in.issues:writeis a universal union permission (319/319) despite only 262 agent jobs readingissuesdirectly — every workflow's safe-outputs job requests issue-write regardless of whether the workflow creates issues.create_discussion_workflowsstayed flat at 92 — consistent with one new multi-engine comparison workflow bundle rather than broad diversification.audits(85.9%) — this very analyzer is representative of the typical discussion-producing workflow, not an outlier.Historical trends (vs. 2026-10-02)
Two safe-output types disappeared entirely this cycle:
approve_workflow_run(1→0) anddismiss_pull_request_review(1→0, down from 2 last-last cycle), whilepublish-essential-issuesappeared for the first time (0→1).Recommendations
noop/missing_tool/missing_datasafe-output handling and backfill for consistency.GH_AW_SAFE_OUTPUTS_CONFIGat all is an intentional minimal workflow, not a compile regression.issues:writeas an expected baseline union permission (required by the safe-outputs dispatcher job) rather than a per-workflow design choice.References:
All reactions