nektos/act
66.1
Adequate · 24 September 2026
14.2k
lines of production code
Go
with JavaScript
5
measurements over time
What this system is
This system is a Go-based GitHub Actions runner that executes CI/CD workflows by managing containerized steps and action execution. It provides a complete execution environment with local artifact caching, Docker-based container management, and support for Node.js and Docker-based actions. The system handles workflow parsing, expression evaluation, and strict schema validation to ensure reliable and secure automation of software delivery pipelines.
How it got here
2019–2020 — Core runner and CLI architecture
10 changes.
This period focused on establishing the foundational architecture for the GitHub Actions runner, introducing a modular CLI structure and a Go-based execution engine for processing workflows and actions. The work included implementing container execution via Docker, adding common utilities for authentication and context management, and establishing a robust test suite with various action fixtures.
2021–2023 — runner and expression engine enhancements
10 changes.
This period focused on expanding the GitHub Actions compatibility layer, introducing a new expression parser with built-in functions and a local artifact cache for improved performance. The runner was updated to support Node.js 16 and 20 runtimes, while also implementing pre/post step execution and Git metadata utilities.
2024–2025 — pkg/filecollector and schema validation
6 changes.
This period focused on modularizing file collection logic into a new package and enforcing strict schema validation for GitHub Actions workflows. The team also expanded test coverage for composite actions, post-step failures, and Docker environment variable handling.
Features
Add GitHub Actions Artifacts v4 backend
The artifact server now supports the GitHub Actions v4 API, enabling workflows to upload and download artifacts using the modern signed-upload URL flow. This adds new endpoints for creating, finalizing, listing, and downloading artifacts, alongside the legacy upload/download routes.
pkg/artifacts · high confidence
Add GitHub CLI token retrieval utility
A new utility function GetToken has been added to the GitHub package, which executes the 'gh auth token' command to retrieve the current user's authentication token. This change enables the application to programmatically access GitHub credentials via the CLI, with a corresponding test added to verify the function's behavior.
pkg/gh · high confidence
Add Node.js 16 action test data
Added a new test fixture for Node.js 16 actions, including the action definition (action.yml), the compiled JavaScript bundle (dist/index.js), the source entry point (index.js), and all required npm dependencies (such as @actions/core, @actions/github, and @octokit packages). This enables the runner to execute and validate actions built with Node.js 16.
pkg/runner/testdata/actions/node16 · high confidence
Add Node.js 20 runtime test data for the runner
Added a new test fixture for the GitHub Actions runner that supports the Node.js 20 runtime. This includes the action definition (action.yml), the compiled JavaScript bundle (dist/index.js), the source entry point (index.js), and all necessary node\_modules dependencies (including @actions/core, @actions/github, @octokit packages) required to execute actions using the Node.js 20 environment.
pkg/runner/testdata/actions/node20 · high confidence
Add common utilities for authentication, execution, and context management
The \pkg/common\ package introduces several new utilities to support workflow execution and job management. It adds JWT-based authorization token creation and parsing (\auth.go\), a pipeline and parallel executor framework for managing workflow steps (\executor.go\), and context helpers for graceful job cancellation (\context.go\, \job\_error.go\). Additionally, it provides a Cartesian product generator for matrix builds (\cartesian.go\), a line writer for structured log processing (\line\_writer.go\), and an outbound IP address resolver (\outbound\_ip.go\).
pkg/common · high confidence
Add workflow pattern matching for paths and branches
The \pkg/workflowpattern\ package now provides logic to match file paths and branch names against glob-style patterns (e.g., \feature/\\, \\\*\), supporting both inclusion and exclusion rules. This enables the system to determine which workflows should be skipped or filtered based on changed files or triggered branches, with trace logging for debugging pattern matches.
pkg/workflowpattern · high confidence
Added Node.js 12 action test data
Added a new test fixture for a Node.js 12-based GitHub Action, including the action metadata, compiled JavaScript, and all required npm dependencies (such as @actions/core, @actions/github, and @octokit packages). This provides a complete, self-contained example of a Node 12 action for use in the runner's test suite.
pkg/runner/testdata/actions/node12 · high confidence
Extracted file collection logic into a new \`pkg/filecollector\` package
The file collection and copying logic has been refactored into a new \pkg/filecollector\ package. This introduces a \FileCollector\ that supports pluggable handlers (\TarCollector\ for tar archives and \CopyCollector\ for direct filesystem copies), allowing the system to collect files from a source path while respecting gitignore patterns and handling symlinks. The change includes the implementation of the collector and its associated test suite.
pkg/filecollector · high confidence
Introduce Docker-based container execution engine
The \pkg/container\ package has been refactored to use the Docker SDK for all container operations. This introduces a new \Container\ interface and concrete implementations for building, pulling, and running Docker images, as well as managing Docker networks. Users will now interact with a consistent container abstraction that supports platform-specific image pulls, custom authentication via \\~/.docker/config.json\ or explicit credentials, and network isolation. The change also includes a new \DOCKER\_LICENSE\ file to comply with the Apache 2.0 license of the Docker CLI codebase, which was adapted for the \docker\_cli.go\ and \docker\_cli\_test.go\ files.
pkg/container · high confidence
Introduce hashfiles module for computing file content hashes
A new JavaScript module at pkg/runner/hashfiles/index.js has been added to the runner. This module implements the logic for computing SHA-256 hashes of files matching specified patterns, supporting symbolic link traversal and filtering out non-matching or directory entries. It outputs the resulting hash via the GitHub Actions workflow command protocol, enabling workflows to reliably reference file content hashes in subsequent steps.
pkg/runner/hashfiles · high confidence
Introduce local artifact cache for runners
A new local artifact cache implementation has been added to the runner, providing a cache handler that stores and retrieves cached files using a BoltDB-backed storage system. The feature includes a new HTTP handler that manages cache lifecycle (reserve, upload, commit, find, clean) and supports configuring a custom external URL for the cache server. This enables the runner to cache dependencies and artifacts locally, improving workflow speeds by reusing previously cached data.
pkg/artifactcache · high confidence
Introduce new CLI structure and configuration handling
The \cmd\ package is refactored into a new modular structure, introducing \Input\ to manage CLI flags and options, and \dir.go\ to handle user home and cache directory paths. The \root.go\ file now defines the root command and argument parsing, while \secrets.go\ handles secret input and case-insensitivity. New files include \graph.go\ for workflow visualization, \list.go\ for listing workflows, \notices.go\ for version check notifications, \platforms.go\ for platform mapping, and \input.go\ for resolving file paths. Tests are added in \execute\_test.go\ and \root\_test.go\ to cover argument parsing, secret reading, and flag handling.
cmd · high confidence
Introduce new Go-based action and expression evaluation infrastructure
The \pkg/runner\ package now includes a new set of files (\action.go\, \action\_cache.go\, \action\_composite.go\, \command.go\, \expression.go\, and their tests) that implement the core logic for parsing, caching, and executing GitHub Actions. This includes a new \GoGitActionCache\ for fetching remote actions, logic to handle composite actions, and a dedicated expression evaluator for processing workflow expressions. These changes provide the foundational components for the runner to process actions and evaluate conditions, replacing or supplementing previous ad-hoc implementations.
pkg/runner · high confidence
Introduce new git utility package for repository metadata and reference resolution
A new \pkg/common/git\ package was added, providing functions to retrieve the current git revision, identify the repository slug (supporting GitHub and AWS CodeCommit), and resolve the current git reference (tag or branch) by iterating through repository heads. The implementation uses the \go-git\ library and includes comprehensive unit tests for these capabilities.
pkg/common/git · high confidence
New expression parser and built-in functions for workflow expressions
The \pkg/exprparser\ package has been replaced with a new implementation that uses the \actionlint\ library to parse and evaluate expressions. This update introduces built-in functions for string manipulation (\contains\, \startsWith\, \endsWith\), array joining (\join\), and data serialization (\toJSON\, \fromJSON\). It also adds a \hashFiles\ function to compute SHA-256 hashes of file paths, supporting glob patterns and exclusions. Comprehensive unit tests have been added to verify the new evaluation logic and function behaviors.
pkg/exprparser · high confidence
Repository initialization and tooling configuration
The repository was initialized with a comprehensive set of configuration files and documentation. This includes the Go source code (main.go, main\_test.go), a Makefile for build and test automation, and a version file (0.2.89). Additionally, the repository now includes configuration for code quality and security tools: .golangci.yml for Go linting, .gitleaks.toml and .gitleaksignore for secret scanning, .codespellrc for spelling checks, .editorconfig for code formatting, .prettierrc.yml for YAML/JSON formatting, .markdownlint.yml for markdown style, and .mega-linter.yml for CI linting. The project also provides a CONTRIBUTING.md guide, an IMAGES.md reference for Docker images, and a detailed CLAUDE.md for AI-assisted development. The README.md was expanded with usage instructions and badges.
(repo-wide) · high confidence
Behavioural changes
Introduce YAML anchor alias resolution and workflow/job validation
The model package now resolves YAML anchor aliases before parsing workflows and actions, preventing errors from circular or unresolved references. Additionally, the workflow planner now validates job names against a strict regex, rejecting names that do not start with a letter or underscore and contain only alphanumeric characters, hyphens, or underscores. This ensures that invalid job names in workflow files are caught early with a clear error message.
pkg/model · high confidence
Introduce strict schema validation for GitHub Actions workflows and actions
The \pkg/schema\ package now enforces strict validation rules for GitHub Actions workflow and action files. This change introduces comprehensive JSON schemas (\workflow\_schema.json\ and \action\_schema.json\) and Go-based validation logic (\schema.go\) that check for valid event triggers, job configurations, step definitions, and function calls. Users will now see more precise error messages when their workflow YAML contains invalid structures, unsupported event types, or incorrect function usage, ensuring that only well-formed actions and workflows are accepted.
pkg/schema · high confidence
Support for pre and post steps in actions
The runner now supports pre and post steps for both regular and composite actions. Test data in \pkg/runner/testdata/uses-action-with-pre-and-post-step\ and \pkg/runner/testdata/uses-composite-with-pre-and-post-steps\ demonstrates that actions can now define \pre\ and \post\ scripts in their \action.yml\ (e.g., \pre.js\, \post.js\), which are executed before and after the main action logic, respectively.
pkg/runner/testdata/uses-action-with-pre-and-post-step, pkg/runner/testdata/uses-composite-with-pre-and-post-steps · medium confidence
Fixes
Added test fixtures for post-step execution
Added test data under pkg/runner/testdata/ensure-post-steps, including a composite action, a node-based action with a failing post-step, and a workflow file to verify that post-steps are executed.
pkg/runner/testdata/ensure-post-steps · medium confidence
Fix Docker action test data for host environment variable tests
Added the complete test fixture for the Docker action host environment variable scenario, including the Dockerfile, action.yml, entrypoint.sh, and push.yml workflow. This ensures the runner correctly handles environment variables and file system access within the step container.
pkg/runner/testdata/docker-action-host-env · medium confidence
Test coverage
Add local Docker action test fixture; Add test data for post-step failure handling; Add test fixtures for composite action input collision and shadowing; Add test fixtures for working-directory support.
Dependencies
Updated Go dependencies and test fixtures
The project's Go dependencies have been updated, including major version bumps for the Docker client and CLI, Moby BuildKit, and various other libraries like logrus, go-git, and actionlint. Additionally, test fixtures for the Node 12 action runner have been updated with newer versions of the @actions/core, @actions/github, and @octokit packages to match the updated dependency graph.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 67 → 66 (-1.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 76 (+5.5)
- Architecture 100 → 98 (-2.3)
- Maturity 68 → 66 (-1.6)
- Readiness 76 → 76 (-0.7)
- Security 61 → 59 (-2.5)
Resolved (87)
- (anonymous) (cognitive 17) (pkg/runner/hashfiles/index.js)
- (anonymous) (cognitive 17) (pkg/runner/hashfiles/index.js)
- (anonymous) (cognitive 47) (pkg/runner/hashfiles/index.js)
- (anonymous) (cyclomatic 26) (pkg/runner/hashfiles/index.js)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 3) (pkg/runner/action.go)
- Duplicated block (11 lines × 2) (pkg/model/github_context.go)
- Duplicated block (11 lines × 2) (pkg/runner/expression.go)
- Duplicated block (12 lines × 2) (pkg/artifactcache/handler.go)
- Duplicated block (12 lines × 2) (pkg/container/docker_images.go)
- Duplicated block (12 lines × 2) (pkg/container/docker_run.go)
- Duplicated block (12 lines × 2) (pkg/exprparser/interpreter.go)
- Duplicated block (12 lines × 2) (pkg/runner/run_context.go)
- Duplicated block (13 lines × 2) (pkg/artifactcache/handler.go)
- Duplicated block (13 lines × 2) (pkg/container/docker_network.go)
- Duplicated block (13 lines × 2) (pkg/container/host_environment.go)
- Duplicated block (13 lines × 2) (pkg/runner/action_composite.go)
- Duplicated block (15 lines × 2) (pkg/runner/action.go)
- …and 67 more
New (200)
- (anonymous)::(anonymous)::_getAgent (cognitive 31) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::_getAgent (cyclomatic 24) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::constructor (cognitive 16) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::ensureAbsoluteRoot (cognitive 23) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::expand (cognitive 58) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::expand (cyclomatic 26) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::fixupPattern (cognitive 17) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::getLiteral (cognitive 29) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::getLiteral (cyclomatic 17) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::globGenerator::globGenerator_1 (cognitive 25) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::globGenerator::globGenerator_1 (cyclomatic 17) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::match (cognitive 19) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::matchOne (cognitive 52) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::matchOne (cyclomatic 26) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::parse (cognitive 83) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::parse (cyclomatic 64) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::range (cognitive 20) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::toString (cognitive 17) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::v1 (cognitive 23) (pkg/runner/hashfiles/index.js)
- (anonymous)::(anonymous)::v1 (cyclomatic 23) (pkg/runner/hashfiles/index.js)
- …and 180 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nektos/act was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4f411281417e88660bea1c1a1749aa71ae0bd60f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.