Ghanon
Ghanon(dorf) - A strict GitHub Actions workflow linter that validates your workflows against best practices.
🎯 What is Ghanon?
Ghanon is a powerful linter for GitHub Actions workflows that goes beyond basic YAML validation. It validates your .github/workflows/*.yml files against the official GitHub Actions schema using Pydantic models and enforces best practices with custom validation rules.
Key Features
- 📋 Complete Schema Validation: Validates against the full GitHub Actions Workflow Schema
- 🎯 Precise Error Reporting: Shows exact line numbers where validation errors occur
- ✨ Best Practices Enforcement: Custom validators that catch common anti-patterns and security issues
- 🔒 Security-First: Enforces principle of least privilege for secrets and permissions
- 🚀 CI/CD Ready: Easy to integrate into your continuous integration pipelines
- 💯 Type-Safe: Built with Pydantic for robust validation
Best Practices Enforced
- ❌ Discourages
secrets: inherit(principle of least privilege) - 🔍 Validates job IDs, step configurations, and runner specifications
- 🛡️ Checks permissions, concurrency settings, and environment configurations
📦 Installation
Ghanon requires Python 3.14 or higher.
Using pip
pip install ghanon
Using pipx (recommended for CLI tools)
pipx install ghanon
Using uv
uv tool install ghanon
🚀 Usage
Command Line
Validate a single workflow file:
ghanon path/to/workflow.yml
Validate all workflows in your repository:
ghanon .github/workflows/*.yml
In CI/CD Pipelines
Add Ghanon to your GitHub Actions workflow:
name: Validate Workflows
on:
pull_request:
paths:
- '.github/workflows/**'
push:
branches:
- main
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.14'
- name: Install Ghanon
run: pip install ghanon
- name: Validate workflows
run: ghanon .github/workflows/*.yml
📖 Example Output
When Ghanon finds issues in your workflow:
❌ Validation failed for workflow.yml
Error at line 15 (jobs.build.secrets):
Do not use `secrets: inherit`. Define secrets explicitly for principle of least privilege.
🛠️ Development
Prerequisites
Setup
# Clone the repository
git clone https://github.com/nikoheikkila/ghanon.git
cd ghanon
# Install dependencies
task install
# Run the linter
uv tool install .
ghanon path/to/workflow.yml
Testing
Ghanon maintains 100% test coverage:
# Run full test suite (format, lint, test)
task test
# Run only unit tests
task test:unit
# Watch mode for TDD
task test:watch
Code Quality
# Lint code
task lint
# Format code
task format
🤝 Contributing
Contributions are welcome! Please read our Contributing Guidelines and Code of Conduct before submitting pull requests.
Quick Start for Contributors
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Make your changes following our conventions
- Ensure all tests pass (
task test) - Commit using Conventional Commits
- Push to your fork and submit a pull request
📄 License
This project is licensed under the MIT License - see the LICENSE file for details.
🙏 Acknowledgments
- Built with Pydantic for robust validation
- Schema based on SchemaStore's GitHub Workflow Schema
- Inspired by the need for better GitHub Actions workflow validation
📞 Support
If you encounter any issues or have questions:
Made with ❤️ by Niko Heikkilä
Metadata
Release files for ghanon 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ghanon-0.2.1.tar.gz | 86.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ghanon-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 119.6 kB
Release files / ghanon-0.2.1.tar.gz
| Download URL | ghanon-0.2.1.tar.gz |
|---|---|
| Size | 86.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0424e1958214f7941bf0908608d0130137a9689fd56bf1abc201413f1224dffd
|
|
BLAKE2b-256 checksum How to use checksums |
fb114b4a1092b61c9ce638c73c31961236b8b8285c470acc2a1348d55d8a0e05
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 4, 2025.
Transparency logRelease files / ghanon-0.2.1-py3-none-any.whl
| Download URL | ghanon-0.2.1-py3-none-any.whl |
|---|---|
| Size | 33.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
12616e21e187832746d78b0390bf49e46b2c88b6ba03771e20ef0061008a4e05
|
|
BLAKE2b-256 checksum How to use checksums |
19c72b6740d3e063f658d956131b42fe41cd3002c5ea9964000a64f00a44b70f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 4, 2025.
Transparency log