Skip to main content

Ghanon

Ghanon(dorf) - A strict GitHub Actions workflow linter that validates your workflows against best practices.

PyPI version Python Version License: MIT Test Coverage Code style: ruff

🎯 What is Ghanon?

Ghanon is a powerful linter for GitHub Actions workflows that goes beyond basic YAML validation. It validates your .github/workflows/*.yml files against the official GitHub Actions schema using Pydantic models and enforces best practices with custom validation rules.

Key Features

  • 📋 Complete Schema Validation: Validates against the full GitHub Actions Workflow Schema
  • 🎯 Precise Error Reporting: Shows exact line numbers where validation errors occur
  • ✨ Best Practices Enforcement: Custom validators that catch common anti-patterns and security issues
  • 🔒 Security-First: Enforces principle of least privilege for secrets and permissions
  • 🚀 CI/CD Ready: Easy to integrate into your continuous integration pipelines
  • 💯 Type-Safe: Built with Pydantic for robust validation

Best Practices Enforced

  • ❌ Discourages secrets: inherit (principle of least privilege)
  • 🔍 Validates job IDs, step configurations, and runner specifications
  • 🛡️ Checks permissions, concurrency settings, and environment configurations

📦 Installation

Ghanon requires Python 3.14 or higher.

Using pip

pip install ghanon

Using pipx (recommended for CLI tools)

pipx install ghanon

Using uv

uv tool install ghanon

🚀 Usage

Command Line

Validate a single workflow file:

ghanon path/to/workflow.yml

Validate all workflows in your repository:

ghanon .github/workflows/*.yml

In CI/CD Pipelines

Add Ghanon to your GitHub Actions workflow:

name: Validate Workflows

on:
  pull_request:
    paths:
      - '.github/workflows/**'
  push:
    branches:
      - main

jobs:
  lint:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      
      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: '3.14'
      
      - name: Install Ghanon
        run: pip install ghanon
      
      - name: Validate workflows
        run: ghanon .github/workflows/*.yml

📖 Example Output

When Ghanon finds issues in your workflow:

❌ Validation failed for workflow.yml

Error at line 15 (jobs.build.secrets):
  Do not use `secrets: inherit`. Define secrets explicitly for principle of least privilege.

🛠️ Development

Prerequisites

  • Python 3.14+
  • Task (task runner)
  • uv (package manager)

Setup

# Clone the repository
git clone https://github.com/nikoheikkila/ghanon.git
cd ghanon

# Install dependencies
task install

# Run the linter
uv tool install .
ghanon path/to/workflow.yml

Testing

Ghanon maintains 100% test coverage:

# Run full test suite (format, lint, test)
task test

# Run only unit tests
task test:unit

# Watch mode for TDD
task test:watch

Code Quality

# Lint code
task lint

# Format code
task format

🤝 Contributing

Contributions are welcome! Please read our Contributing Guidelines and Code of Conduct before submitting pull requests.

Quick Start for Contributors

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Make your changes following our conventions
  4. Ensure all tests pass (task test)
  5. Commit using Conventional Commits
  6. Push to your fork and submit a pull request

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🙏 Acknowledgments

📞 Support

If you encounter any issues or have questions:


Made with ❤️ by Niko Heikkilä

Metadata

Release files for ghanon 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ghanon 0.2.1
File Size Uploaded
ghanon-0.2.1.tar.gz 86.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ghanon 0.2.1
File Interpreter ABI Platform
ghanon-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 119.6 kB

Release files / ghanon-0.2.1.tar.gz

Download URL ghanon-0.2.1.tar.gz
Size 86.3 kB
Tags Source
SHA-256 checksum
How to use checksums
0424e1958214f7941bf0908608d0130137a9689fd56bf1abc201413f1224dffd
BLAKE2b-256 checksum
How to use checksums
fb114b4a1092b61c9ce638c73c31961236b8b8285c470acc2a1348d55d8a0e05
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 4, 2025.

Transparency log

Release files / ghanon-0.2.1-py3-none-any.whl

Download URL ghanon-0.2.1-py3-none-any.whl
Size 33.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
12616e21e187832746d78b0390bf49e46b2c88b6ba03771e20ef0061008a4e05
BLAKE2b-256 checksum
How to use checksums
19c72b6740d3e063f658d956131b42fe41cd3002c5ea9964000a64f00a44b70f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 4, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page