GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit
Validate GitHub Actions workflow YAML for syntax errors, missing required fields, deprecated commands, mutable action refs, outdated action versions, and broken job dependencies. Get per-job results with fix hints in real time.
How to Use GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit
How to Use the GitHub Actions Workflow Validator
Step 1: Paste Your Workflow YAML
Copy your .github/workflows/*.yml file and paste it into the input area. Validation runs instantly as you type using js-yaml for parsing followed by schema checks.
Step 2: Review Workflow-Level Issues
The "Workflow" section shows issues at the top level of the file — missing on triggers, missing jobs, no permissions block, or unknown trigger event names.
Step 3: Review Per-Job Results
Each job in the workflow gets its own result card. The card header shows the job name and a compact issue count (e.g. 2e 1w 3i for 2 errors, 1 warning, 3 info). Click any issue row to expand a fix hint.
Step 4: Load an Example
Use the example buttons to see validation in action:
- Broken Workflow — missing
on, noruns-on, deprecated::set-output, step with no action - Outdated & Unsafe — mutable
@mainref, outdated actions, brokenneedsreference - Best-Practice — clean workflow with
permissions, pinned actions,timeout-minutes
Checks Performed
| Severity | Check | Details |
|---|---|---|
| Error | Missing on | Required trigger field absent |
| Error | Missing jobs | Required jobs section absent |
| Error | Missing runs-on | Job has no runner defined |
| Error | Missing steps | Job has no steps |
| Error | Step without uses or run | Step does nothing |
| Error | Step with both uses and run | Conflicting step fields |
| Error | Action with no @ pin | No version reference at all |
| Error | Action pinned to mutable branch | @main, @master, @HEAD etc. |
| Error | Broken needs reference | Depends on non-existent job |
| Error | Invalid cron expression | Wrong number of fields in schedule |
| Warning | Outdated action version | Old actions/checkout@v2 etc. |
| Warning | Floating major-version tag | @v1 may receive breaking updates |
| Warning | Deprecated ::set-output | Should use $GITHUB_OUTPUT |
| Warning | Deprecated ::save-state | Should use $GITHUB_STATE |
| Warning | Deprecated ::set-env | Should use $GITHUB_ENV |
| Warning | continue-on-error: true | Job failure will be hidden |
| Info | Unknown trigger event | Not a standard GHA event name |
| Info | Missing workflow name | Harder to navigate in Actions UI |
| Info | Missing job name | Job appears with its ID only |
| Info | No timeout-minutes | Job can run indefinitely |
| Info | No permissions | Default broad token permissions |
Frequently Asked Questions
Most Viewed Tools
Screen Size Converter — Diagonal Dimension Tool
Calculate screen width and height from diagonal size and aspect ratio. Convert between inches and centimeters for displays, TVs, and monitors with instant dimension calculations.
Use Tool →TOTP Code Generator — 2FA Testing Tool
Generate time-based one-time passwords from a TOTP secret key. Enter your base32 secret, choose a period and digit length, and get the current and next codes with a live countdown timer. Useful for testing and debugging 2FA integrations.
Use Tool →JSON to Zod — Schema Generator
Generate Zod validation schema code from a JSON sample object. Infers z.string(), z.number(), z.boolean(), z.array(), z.object(), and z.null() types automatically. Handles nested objects, arrays of objects with optional field detection, and outputs copy-ready TypeScript with import and z.infer type alias.
Use Tool →JSONL Formatter — Line-by-Line Validator
Format, validate, and inspect JSON Lines (JSONL) and NDJSON files. Validates each line individually, reports parse errors by line number, outputs compact JSONL or a pretty-print preview, and lets you download the cleaned file.
Use Tool →Password Entropy Calculator — Crack Time Estimator
Calculate the information-theoretic bit entropy of any password or API key. Detects character set pools automatically, shows the total number of possible combinations, and estimates crack time across five attack scenarios from rate-limited web logins to GPU cracking clusters.
Use Tool →TLS Cipher Suite Checker — Strength Analyzer
Check TLS protocol version compatibility and cipher suite strength ratings against current best practices. Supports IANA and OpenSSL cipher names — rates each suite as Strong, Weak, or Deprecated and explains why.
Use Tool →Secret Scanner — API Key & Credential Detector
Scan pasted text, code, or config files for accidentally exposed API keys, tokens, passwords, and private keys. Detects 50+ secret types across AWS, GitHub, Stripe, OpenAI, and more — all client-side, nothing leaves your browser.
Use Tool →TOML Config Validator — Syntax Error Finder
Validate TOML configuration file syntax and report errors with line numbers. Paste any TOML content — Cargo.toml, pyproject.toml, config.toml — and instantly see a green checkmark with key counts and structure stats, or a precise error message pointing to the exact line. Includes a collapsible JSON structure preview to confirm what was parsed.
Use Tool →Related DevOps & Infrastructure Tools
Kubernetes YAML Validator — K8s Manifest Schema & Security Audit
Validate Kubernetes YAML manifests for syntax errors and required field completeness. Checks Deployments, Services, Ingress, ConfigMaps, Secrets, PVCs, HPAs, CronJobs, and more — with per-document results and fix hints.
Use Tool →HTTP Header Analyzer — Security & CORS Audit
Parse and analyze HTTP request or response headers. Identifies categories, explains each header, flags missing security headers, and detects duplicates or suspicious values — entirely in your browser.
Use Tool →API Response Formatter — JSON Pretty Printer
Format and beautify API responses for better readability. JSON formatter with minify and prettify options.
Use Tool →robots.txt Validator — Crawl Rule Checker
Validate your robots.txt file against the Robots Exclusion Protocol. Checks directive syntax, path formats, Crawl-delay values, and Sitemap URLs. Previews crawl rules per user-agent group. Free and runs entirely in your browser.
Use Tool →Port Number Lookup — Common TCP/UDP Service & Protocol Database
Searchable reference for 80+ well-known TCP and UDP ports. Look up any port number or service name to see the official protocol, service description, port range (well-known/registered), and security recommendations for risky ports.
Use Tool →Robots.txt Generator — Crawler Control Tool
Generate robots.txt file to control search engine crawlers. Create user-agent rules, allow/disallow paths, set crawl delays, and add sitemap URLs. Perfect for managing bot access to your website.
Use Tool →Query String Parser — URL Parameter Decoder
Parse URL query strings into readable key-value pairs. Decode parameters and inspect URL search queries with ease.
Use Tool →Dockerfile Linter — Optimize & Secure Your Container Builds
Lint Dockerfile instructions for best practices, security issues, and layer optimization. Flags unpinned base images, root user, ADD vs COPY, apt-get mistakes, shell-form CMD, and more — with fix guidance for each issue.
Use Tool →Share Your Feedback
Help us improve this tool by sharing your experience