Introduction
flowpact finds what gets lost between GitHub Actions workflows — missing inputs, dead outputs, inherited secrets and matrix legs that silently run with empty values.
Large CI setups grow into a tree: one pipeline.yml with dozens (or hundreds) of workflow_call inputs fans out to
reusable workflows, which call more reusable workflows and composite actions. Each level passes a different subset of
values down and hands outputs back up. Eventually nobody can answer:
- Where does this input actually go?
- Is anything we pass ignored, or anything we read never passed?
- Does every matrix leg get every value it needs?
GitHub does not help: a missing matrix key, an undeclared secret or an optional input without a default all evaluate to an empty string — no error, no warning, a green run.
What flowpact does
flowpact parses your workflows and local actions into a data-flow graph — every input, secret, env var, matrix key and output, where it is defined and where it is read, across every level of nesting — and runs rules over it.
Lint
Contracts
flowpact check fails on drift and marks breaking interface changes.Trace and graph
Explain
flowpact explain FP401 prints the same in the terminal.GitHub Action
Configure
Quick start
npx flowpact lint # find problems
npx flowpact generate # lock the interfaces in .github/flowpact/
npx flowpact check # lint + fail when the workflows no longer match the contractsRun it at the root of a repository. See Getting started for installation options and how to read the output.