GitHub Actions SHA Rerun Debt Audit
Use this skill to detect commits that trigger repeated GitHub Actions reruns and failed outcomes across multiple workflows.
What this skill does
- Reads GitHub Actions run JSON exports
- Correlates attempt history by run id and latest outcome per run
- Aggregates rerun debt by repository + commit SHA
- Scores risk using rerun rate, failed-run count, workflow spread, and wasted rerun minutes
- Emits severity (
ok, warn, critical) for CI gates
Inputs
Optional:
RUN_GLOB (default: artifacts/github-actions/*.json)
TOP_N (default: 20)
OUTPUT_FORMAT (text or json, default: text)
MIN_RUNS (minimum runs per SHA, default: 3)
WARN_RERUN_RATE (0..1, default: 0.25)
CRITICAL_RERUN_RATE (0..1, default: 0.45)
WARN_FAILED_RUNS (default: 2)
CRITICAL_FAILED_RUNS (default: 4)
WARN_WASTED_MINUTES (default: 25)
CRITICAL_WASTED_MINUTES (default: 75)
WARN_WORKFLOWS (distinct workflows affected, default: 2)
CRITICAL_WORKFLOWS (default: 4)
WORKFLOW_MATCH / WORKFLOW_EXCLUDE (regex, optional)
BRANCH_MATCH / BRANCH_EXCLUDE (regex, optional)
EVENT_MATCH / EVENT_EXCLUDE (regex, optional)
REPO_MATCH / REPO_EXCLUDE (regex, optional)
HEAD_SHA_MATCH / HEAD_SHA_EXCLUDE (regex, optional)
FAILURE_CONCLUSIONS (comma-separated, default: failure,cancelled,timed_out,startup_failure,action_required)
FAIL_ON_CRITICAL (0 or 1, default: 0)
Collect run JSON
gh run view <run-id> --attempt <attempt> \
--json databaseId,runAttempt,workflowName,event,headBranch,headSha,conclusion,createdAt,updatedAt,runStartedAt,url,repository \
> artifacts/github-actions/run-<run-id>-attempt-<attempt>.json
Run
Text report:
RUN_GLOB='artifacts/github-actions/*.json' \
bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh
JSON output + fail gate:
RUN_GLOB='artifacts/github-actions/*.json' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh
Run against bundled fixtures:
RUN_GLOB='skills/github-actions-sha-rerun-debt-audit/fixtures/*.json' \
bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh
Output contract
- Exit
0 in report mode (default)
- Exit
1 when FAIL_ON_CRITICAL=1 and one or more SHA groups are critical
- Text mode prints summary + ranked SHA risk groups
- JSON mode prints summary + ranked groups + critical groups
1---2name: github-actions-sha-rerun-debt-audit3description: Audit rerun debt by commit SHA to find commits that repeatedly burn CI minutes across workflows.4---56# GitHub Actions SHA Rerun Debt Audit78Use this skill to detect commits that trigger repeated GitHub Actions reruns and failed outcomes across multiple workflows.910## What this skill does11- Reads GitHub Actions run JSON exports12- Correlates attempt history by run id and latest outcome per run13- Aggregates rerun debt by repository + commit SHA14- Scores risk using rerun rate, failed-run count, workflow spread, and wasted rerun minutes15- Emits severity (`ok`, `warn`, `critical`) for CI gates1617## Inputs18Optional:19- `RUN_GLOB` (default: `artifacts/github-actions/*.json`)20- `TOP_N` (default: `20`)21- `OUTPUT_FORMAT` (`text` or `json`, default: `text`)22- `MIN_RUNS` (minimum runs per SHA, default: `3`)23- `WARN_RERUN_RATE` (0..1, default: `0.25`)24- `CRITICAL_RERUN_RATE` (0..1, default: `0.45`)25- `WARN_FAILED_RUNS` (default: `2`)26- `CRITICAL_FAILED_RUNS` (default: `4`)27- `WARN_WASTED_MINUTES` (default: `25`)28- `CRITICAL_WASTED_MINUTES` (default: `75`)29- `WARN_WORKFLOWS` (distinct workflows affected, default: `2`)30- `CRITICAL_WORKFLOWS` (default: `4`)31- `WORKFLOW_MATCH` / `WORKFLOW_EXCLUDE` (regex, optional)32- `BRANCH_MATCH` / `BRANCH_EXCLUDE` (regex, optional)33- `EVENT_MATCH` / `EVENT_EXCLUDE` (regex, optional)34- `REPO_MATCH` / `REPO_EXCLUDE` (regex, optional)35- `HEAD_SHA_MATCH` / `HEAD_SHA_EXCLUDE` (regex, optional)36- `FAILURE_CONCLUSIONS` (comma-separated, default: `failure,cancelled,timed_out,startup_failure,action_required`)37- `FAIL_ON_CRITICAL` (`0` or `1`, default: `0`)3839## Collect run JSON4041```bash42gh run view <run-id> --attempt <attempt> \43 --json databaseId,runAttempt,workflowName,event,headBranch,headSha,conclusion,createdAt,updatedAt,runStartedAt,url,repository \44 > artifacts/github-actions/run-<run-id>-attempt-<attempt>.json45```4647## Run4849Text report:5051```bash52RUN_GLOB='artifacts/github-actions/*.json' \53bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh54```5556JSON output + fail gate:5758```bash59RUN_GLOB='artifacts/github-actions/*.json' \60OUTPUT_FORMAT=json \61FAIL_ON_CRITICAL=1 \62bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh63```6465Run against bundled fixtures:6667```bash68RUN_GLOB='skills/github-actions-sha-rerun-debt-audit/fixtures/*.json' \69bash skills/github-actions-sha-rerun-debt-audit/scripts/sha-rerun-debt-audit.sh70```7172## Output contract73- Exit `0` in report mode (default)74- Exit `1` when `FAIL_ON_CRITICAL=1` and one or more SHA groups are critical75- Text mode prints summary + ranked SHA risk groups76- JSON mode prints summary + ranked groups + critical groups