⚙️

GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit

Validate GitHub Actions workflow YAML for syntax errors, missing required fields, deprecated commands, mutable action refs, outdated action versions, and broken job dependencies. Get per-job results with fix hints in real time.

Devops ToolsDevOps & Infrastructure
Loading tool...

How to Use GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit

How to Use the GitHub Actions Workflow Validator

Step 1: Paste Your Workflow YAML

Copy your .github/workflows/*.yml file and paste it into the input area. Validation runs instantly as you type using js-yaml for parsing followed by schema checks.

Step 2: Review Workflow-Level Issues

The "Workflow" section shows issues at the top level of the file — missing on triggers, missing jobs, no permissions block, or unknown trigger event names.

Step 3: Review Per-Job Results

Each job in the workflow gets its own result card. The card header shows the job name and a compact issue count (e.g. 2e 1w 3i for 2 errors, 1 warning, 3 info). Click any issue row to expand a fix hint.

Step 4: Load an Example

Use the example buttons to see validation in action:

  • Broken Workflow — missing on, no runs-on, deprecated ::set-output, step with no action
  • Outdated & Unsafe — mutable @main ref, outdated actions, broken needs reference
  • Best-Practice — clean workflow with permissions, pinned actions, timeout-minutes

Checks Performed

SeverityCheckDetails
ErrorMissing onRequired trigger field absent
ErrorMissing jobsRequired jobs section absent
ErrorMissing runs-onJob has no runner defined
ErrorMissing stepsJob has no steps
ErrorStep without uses or runStep does nothing
ErrorStep with both uses and runConflicting step fields
ErrorAction with no @ pinNo version reference at all
ErrorAction pinned to mutable branch@main, @master, @HEAD etc.
ErrorBroken needs referenceDepends on non-existent job
ErrorInvalid cron expressionWrong number of fields in schedule
WarningOutdated action versionOld actions/checkout@v2 etc.
WarningFloating major-version tag@v1 may receive breaking updates
WarningDeprecated ::set-outputShould use $GITHUB_OUTPUT
WarningDeprecated ::save-stateShould use $GITHUB_STATE
WarningDeprecated ::set-envShould use $GITHUB_ENV
Warningcontinue-on-error: trueJob failure will be hidden
InfoUnknown trigger eventNot a standard GHA event name
InfoMissing workflow nameHarder to navigate in Actions UI
InfoMissing job nameJob appears with its ID only
InfoNo timeout-minutesJob can run indefinitely
InfoNo permissionsDefault broad token permissions

Frequently Asked Questions

Most Viewed Tools

🔐

TOTP Code Generator — 2FA Testing Tool

3,078 views

Generate time-based one-time passwords from a TOTP secret key. Enter your base32 secret, choose a period and digit length, and get the current and next codes with a live countdown timer. Useful for testing and debugging 2FA integrations.

Use Tool →
{ }

JSON to Zod — Schema Generator

3,053 views

Generate Zod validation schema code from a JSON sample object. Infers z.string(), z.number(), z.boolean(), z.array(), z.object(), and z.null() types automatically. Handles nested objects, arrays of objects with optional field detection, and outputs copy-ready TypeScript with import and z.infer type alias.

Use Tool →
{}

JSONL Formatter — Line-by-Line Validator

2,978 views

Format, validate, and inspect JSON Lines (JSONL) and NDJSON files. Validates each line individually, reports parse errors by line number, outputs compact JSONL or a pretty-print preview, and lets you download the cleaned file.

Use Tool →
🔐

TLS Cipher Suite Checker — Strength Analyzer

2,629 views

Check TLS protocol version compatibility and cipher suite strength ratings against current best practices. Supports IANA and OpenSSL cipher names — rates each suite as Strong, Weak, or Deprecated and explains why.

Use Tool →
🔍

Secret Scanner — API Key & Credential Detector

2,597 views

Scan pasted text, code, or config files for accidentally exposed API keys, tokens, passwords, and private keys. Detects 50+ secret types across AWS, GitHub, Stripe, OpenAI, and more — all client-side, nothing leaves your browser.

Use Tool →
🔑

Password Entropy Calculator — Crack Time Estimator

2,576 views

Calculate the information-theoretic bit entropy of any password or API key. Detects character set pools automatically, shows the total number of possible combinations, and estimates crack time across five attack scenarios from rate-limited web logins to GPU cracking clusters.

Use Tool →

TOML Config Validator — Syntax Error Finder

2,324 views

Validate TOML configuration file syntax and report errors with line numbers. Paste any TOML content — Cargo.toml, pyproject.toml, config.toml — and instantly see a green checkmark with key counts and structure stats, or a precise error message pointing to the exact line. Includes a collapsible JSON structure preview to confirm what was parsed.

Use Tool →
📺

Screen Size Converter — Diagonal Dimension Tool

2,192 views

Calculate screen width and height from diagonal size and aspect ratio. Convert between inches and centimeters for displays, TVs, and monitors with instant dimension calculations.

Use Tool →

Related DevOps & Infrastructure Tools

🔍

User Agent Parser — Browser & Device Decoder

Parse user agent strings to extract browser, operating system, device, and engine information. Essential for web analytics, device detection, and browser compatibility testing.

Use Tool →
🤖

Robots.txt Generator — Crawler Control Tool

Generate robots.txt file to control search engine crawlers. Create user-agent rules, allow/disallow paths, set crawl delays, and add sitemap URLs. Perfect for managing bot access to your website.

Use Tool →
🤖

robots.txt Validator — Crawl Rule Checker

Validate your robots.txt file against the Robots Exclusion Protocol. Checks directive syntax, path formats, Crawl-delay values, and Sitemap URLs. Previews crawl rules per user-agent group. Free and runs entirely in your browser.

Use Tool →
📋

API Response Formatter — JSON Pretty Printer

Format and beautify API responses for better readability. JSON formatter with minify and prettify options.

Use Tool →
🔍

HTTP Header Analyzer — Security & CORS Audit

Parse and analyze HTTP request or response headers. Identifies categories, explains each header, flags missing security headers, and detects duplicates or suspicious values — entirely in your browser.

Use Tool →
🐋

Dockerfile Linter — Optimize & Secure Your Container Builds

Lint Dockerfile instructions for best practices, security issues, and layer optimization. Flags unpinned base images, root user, ADD vs COPY, apt-get mistakes, shell-form CMD, and more — with fix guidance for each issue.

Use Tool →
🌐

Nginx Config Generator — Performance-Optimized Server Configuration

Generate nginx server block configurations for static sites, reverse proxies, and PHP-FPM setups. Includes SSL best practices, gzip compression, security headers, and upstream blocks — updated in real time as you change options.

Use Tool →
🌐

CIDR Calculator — IPv4 Subnet & Network Range Mapper

Calculate subnet ranges, usable host counts, broadcast addresses, and subnet masks from CIDR notation. Shows network and host addresses in both decimal and binary with color-coded bit visualization.

Use Tool →

Share Your Feedback

Help us improve this tool by sharing your experience

We will only use this to follow up on your feedback