AI NewsDev toolsAnnouncement

Jeff Dickey forks actionlint after upstream stops pushing commits

Jeff Dickey, the author of mise, has forked rhysd/actionlint as jactionlint and started merging the open pull requests the upstream project has not touched since July. 109 stars in four days.

AI News

Editorial2 min read

LinkedInX
GitHub social card for the jdx/jactionlint repository

Image: GitHub

Why it mattersA team that lints its GitHub Actions workflows has an actively maintained drop-in to switch to while the upstream project is quiet, with the same checks and the same playground.

A static checker is only useful while someone is still answering issues. Jeff Dickey, who maintains the dev-tool manager mise, forked the popular GitHub Actions linter rhysd/actionlint on 5 October 2026 as jactionlint, and the README says the fork exists to merge the upstream pull requests and fixes that have piled up.

rhysd/actionlint has 4,308 GitHub stars and its last push to the default branch was 16 July 2026, eleven weeks of quiet with a backlog of community pull requests sitting unmerged. The fork at jdx/jactionlint reports 109 stars four days after it was created, and ships every check the original did plus the ones in those unmerged pull requests.

What the checker finds

The tool reads YAML workflow files and reports issues the author would not catch by eye. The README lists eight classes of check, and the example in it reports seven errors in a 23-line workflow: an unknown key branch on the push trigger, an illegal character in a tag filter, a non-existing runner label linux-latest, an untrusted expression github.event.head_commit.message used straight in an inline script, an actions/setup-node input named node_version instead of node-version, an undefined matrix.platform where only os exists, and a property dereference whose receiver is a string.

Two of those are the ones that matter most. The script-injection warning on github.event.head_commit.message is the public category CVE advisers have been publishing for the last two years, and the actions/setup-node input check reads the action's own schema to notice a typo that silently makes the step do nothing. The checker also runs ShellCheck on inline shell and PyFlakes on inline Python, and validates glob syntax, cron syntax, matrix dependencies and reusable-workflow calls.

How it installs

The fork lists four install paths: mise use -g jactionlint, go install github.com/jdx/jactionlint/cmd/jactionlint@latest, Homebrew, or a released binary from the GitHub releases page. The mise option is relevant: mise use jactionlint without -g writes the version into a project's mise.toml so every contributor and the CI runner get the same checker, and mise-action reads that file. A Docker image and a WebAssembly playground at jactionlint.jdx.dev are also published, with the playground running the whole checker in the browser.

Known limits of a fork like this

The usefulness of a fork like this depends on upstream staying quiet. rhysd/actionlint is not archived, so the original author may resume work and the two projects would then start to diverge. The jactionlint README calls the project "an actively maintained fork" and nothing more; it does not claim the upstream has stopped for good. Teams that pin against a release today can watch both repositories' commit activity before committing to one. The fork is MIT-licensed, matching the original, so a reverse migration is also open.

For a team that lints its workflows in CI, the practical move is to switch the pinned binary and keep every one of the existing rules. The playground URL has changed and the Go API lives at github.com/jdx/jactionlint instead of github.com/rhysd/actionlint, so any Go code that imports the library as a package needs its path updated. Everything else, including the configuration file layout and the names of the checks, matches the upstream the team is already running.

Source

SourceGitHub

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX
Start a project