Reference
apex actions
The action supply chain: what a repository pulls in, the policy over it, and pinning
apex actions [command]Examples
Every action a repository pulls in, least fixed first.
apex actions list acme/webAllow only GitHub's own actions in an organization's workflows; changing it needs organization:write.
apex actions policy acme --mode enforce --allow "actions/*"Open a pull request pinning each action to the commit its version points at.
apex actions pin acme/web --applySubcommands
apex actions list
Every action a repository pulls in, least fixed first
apex actions list [options] <repository>With an API token, needs the permission actions:read.
| Argument | Description |
|---|---|
<repository> | owner/repo |
| Option | Description |
|---|---|
--json | machine-readable output |
apex actions policy
Read or replace an organisation's action policy
apex actions policy [options] <owner>With an API token, needs the permission organization:read.
| Argument | Description |
|---|---|
<owner> | the organisation |
| Option | Description |
|---|---|
--mode <mode> | off · audit · enforce — omit to read the policy rather than change it |
--allow <patterns...> | patterns that may be used; empty means everything not denied |
--deny <patterns...> | patterns that may not be used; deny wins over allow |
--require-pinned | require a commit SHA (or an image digest); a version tag does not count. Omit to permit tags |
--json | machine-readable output |
apex actions pin
Propose pinning every action to the commit its version points at
apex actions pin [options] <repository>With an API token, needs the permission administration:write.
| Argument | Description |
|---|---|
<repository> | owner/repo |
| Option | Description |
|---|---|
--apply | open the pull request; without this the change is only printed |
--json | machine-readable output |