Comparison
How flowpact relates to actionlint, zizmor and the lockfile tools for GitHub Actions.
| Tool | Focus | Overlap with flowpact |
|---|---|---|
| actionlint | Deep single-file checks: expression types, shell scripts (shellcheck), runner labels, action inputs, one level of local workflow_call | Missing/unknown inputs and secrets on direct calls, needs references |
| zizmor, ghalint | Security: injection, permissions, pinning | None |
gh-actions-lockfile, ghasum, actionspack, GitHub's dependencies: lock | Pin action and workflow versions (SHAs, hashes) | None — they lock what code runs, flowpact checks what data flows |
Recommendation: run actionlint and flowpact together. flowpact focuses on what crosses file boundaries and matrix combinations.
Measured on the fixture repositories
The repositories under fixtures/ were linted with both tools:
| Fixture | actionlint | flowpact |
|---|---|---|
incident-matrix — one include entry without config | 0 findings | FP401 naming { name: windows }, the include entry and the receiving input |
deep-nesting — four levels of reusable workflows | 4 findings | the same 4 at identical positions plus 9: optional→required forwarding, dropped pass-throughs, unused inputs/outputs/secrets, an output never written by its step, inherited secrets, an undefined env var |
composite-actions | 4 findings | the same 4 at identical positions plus unused action inputs/outputs |
clean | 0 | 0 |
What only flowpact reports
- per-matrix-combination evaluation of bindings (
FP401,FP402); - values forwarded from optional inputs into required ones (
FP107); - dead inputs, secrets and outputs computed across all callers (
FP104,FP106,FP203,FP303); - step outputs read but never written to
$GITHUB_OUTPUT(FP304); - what
secrets: inheritactually needs (FP204); - call cycles and nesting depth across the whole repository (
FP601,FP602); flowpact tracefor any value, in both directions.
Custom rules
The rule API and code format — how built-in rules are defined and how organization-specific rules fit in.
Impact mode
For publishers of reusable workflows and actions — check that the release impact a pull request declares covers what its changes require, so consumers never get a breaking change as a patch.