Reference

apex actions

The action supply chain: what a repository pulls in, the policy over it, and pinning

apex actions [command]

Examples

Every action a repository pulls in, least fixed first.

apex actions list acme/web

Allow only GitHub's own actions in an organization's workflows; changing it needs organization:write.

apex actions policy acme --mode enforce --allow "actions/*"

Open a pull request pinning each action to the commit its version points at.

apex actions pin acme/web --apply

Subcommands

apex actions list

Every action a repository pulls in, least fixed first

apex actions list [options] <repository>

With an API token, needs the permission actions:read.

Arguments
ArgumentDescription
<repository>owner/repo
Options
OptionDescription
--jsonmachine-readable output

apex actions policy

Read or replace an organisation's action policy

apex actions policy [options] <owner>

With an API token, needs the permission organization:read.

Arguments
ArgumentDescription
<owner>the organisation
Options
OptionDescription
--mode <mode>off · audit · enforce — omit to read the policy rather than change it
--allow <patterns...>patterns that may be used; empty means everything not denied
--deny <patterns...>patterns that may not be used; deny wins over allow
--require-pinnedrequire a commit SHA (or an image digest); a version tag does not count. Omit to permit tags
--jsonmachine-readable output

apex actions pin

Propose pinning every action to the commit its version points at

apex actions pin [options] <repository>

With an API token, needs the permission administration:write.

Arguments
ArgumentDescription
<repository>owner/repo
Options
OptionDescription
--applyopen the pull request; without this the change is only printed
--jsonmachine-readable output