gha-tools
Table of Contents
Installation
pip install gha-tools
You can also use pipx to directly run gha-tools.
Usage
Automatically updating workflow action versions
Use gh-tools autoupdate on a workflow file or directory to automatically
update the action versions to the latest available version.
- By default, the command will not write changes to the file system; use
--writeto have it do that. - You can use
--diffto see what changes would be made. This can be used in conjunction with--write. - You can use
--version-strategy=specificto update to a specific latest version tag instead of the major tag, e.g.v1.2.3instead ofv1. The default is to use the major tag, when available.- You can use
--first-party-version-strategyand--third-party-version-strategyto set different version strategies for first-party and third-party actions respectively.
- You can use
$ gha-tools autoupdate --diff .github/workflows
Updating .github/workflows/publish.yml...
No changes to .github/workflows/publish.yml.
Updating .github/workflows/ci.yml...
--- .github/workflows/ci.yml
+++ .github/workflows/ci.yml
@@ -34,7 +34,7 @@
requirements*txt
- run: 'pip install -e . -r requirements-test.txt'
- run: py.test -vvv --cov .
- - uses: codecov/codecov-action@v2
+ - uses: codecov/codecov-action@v3
Lint:
runs-on: ubuntu-20.04
Version pinning
GitHub Actions best practice is to pin the versions of actions to a specific version SHA, as tags may be mutable.
You can use --pin to have gha-tools autoupdate pin the action to the latest commit SHA for the specified version tag.
If you trust the first-party actions to use immutable tags, use --pin=third_party; otherwise use --pin=all.
$ gha-tools autoupdate --pin=third_party --diff .github/workflows
Updating .github/workflows/test.yml...
--- .github/workflows/test.yml
+++ .github/workflows/test.yml
@@ -12,13 +12,13 @@
lint:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v3
- - uses: akx/pre-commit-uv-action@v0.1.0
+ - uses: actions/checkout@v5
+ - uses: akx/pre-commit-uv-action@19e2cbdb93404ff82f52044f07306443bc0bff7a # v0.1.0
Separate version strategies
You can use different version strategies for first-party and third-party actions. For example, to keep first-party actions on major versions but use specific versions for third-party actions:
$ gha-tools autoupdate --first-party-version-strategy=major --third-party-version-strategy=specific --diff .github/workflows
Updating .github/workflows/test.yml...
--- .github/workflows/test.yml
+++ .github/workflows/test.yml
@@ -5,6 +5,6 @@
steps:
- - uses: actions/checkout@v3
- - uses: actions/setup-python@v4
- - uses: codecov/codecov-action@v3
+ - uses: actions/checkout@v5
+ - uses: actions/setup-python@v6
+ - uses: codecov/codecov-action@v5.5.1
GitHub Rate Limiting
Since this tool uses the GitHub API, you may run into rate limiting issues.
You can specify your GitHub authentication via the environment variable GITHUB_TOKEN or GITHUB_AUTH.
If the value of the environment variable contains a colon (:), it will be interpreted as a username and password;
this is useful with Personal Access Tokens, which are used with your GitHub username.
License
gha-tools is distributed under the terms of the MIT license.
Release files for gha-tools 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gha_tools-0.3.0.tar.gz | 9.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gha_tools-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.4 kB
Release files / gha_tools-0.3.0.tar.gz
| Download URL | gha_tools-0.3.0.tar.gz |
|---|---|
| Size | 9.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1a5931d8ba756c11468680ff5ba390827e22424e2855ba200bf99cc5f7520818
|
|
BLAKE2b-256 checksum How to use checksums |
4e3865d3afeae53c4320ebbddb4992966676dbcce784b5939393d351887a1e56
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 27, 2025.
Transparency logRelease files / gha_tools-0.3.0-py3-none-any.whl
| Download URL | gha_tools-0.3.0-py3-none-any.whl |
|---|---|
| Size | 8.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
de74c93b2f8c1cffcfb9f54c739ce3df0a91816fdce8fbb7f8e1f0c46603672a
|
|
BLAKE2b-256 checksum How to use checksums |
be712d7164b62e99a541c54c17135f218710c15981559915e8594db9f35a152c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 27, 2025.
Transparency log