flowpact · workflow contracts for GitHub Actions

Know exactly what flows between your workflows.

A linter and tracer for deeply nested reusable workflows: missing inputs, dead outputs, inherited secrets and matrix legs that quietly run with empty values.

npx flowpact lint
flowpact lint output showing FP401 for a matrix combination without a config value

Data flow, not just syntax

Follows every input, secret, env var and output across nested reusable workflows and composite actions.

Matrix-aware

Expands include/exclude exactly like GitHub and evaluates each binding per combination — catching the leg that silently gets an empty value.

Explains itself

Every finding has a code, the exact location, the call chain, why it matters, how to fix it and a docs link.

Trace anything

`flowpact trace pipeline.yml:config` shows where a value goes — or, with --up, where it comes from.