flowpactworkflow contracts
Rules

FP603 · remote-unverified

A job calls a reusable workflow in another repository; its interface is not verified.

CodeNameCategoryDefault severity
FP603remote-unverifiedGraph structure🔵 info

Why it matters

flowpact analyzes this repository only, so inputs, secrets and outputs of the remote workflow are taken on trust.

How to fix

Nothing to fix. If the workflow lives in this repository, set repository: owner/repo in the config so it resolves locally.

Configure

Change the severity (or turn the rule off) in .github/flowpact/flowpact.config.yml, by code or by name:

.github/flowpact/flowpact.config.yml
rules:
  FP603: off
  # or: remote-unverified: error

Explain it in the terminal:

flowpact explain FP603

On this page