Overview

Action Dependency Manager

A dependency manager for GitHub Actions that allows you to manage and update your workflow dependencies easily.

July 29, 2026
index

Now more than ever, in a world of vulnerabilities, keeping dependencies up to date is crucial. Due to my role as a maintainer of multiple Repositories across different organizations and personal projects, I found myself spending a lot of time manually updating dependencies. GH-Actions are basically a necessity in my projects. Meaning if 1 of my dependencies is outdated inside a GH-Action, I have to update it in every single workflow file in every single repository.

Thats why I wrote a CLI tool. ADM scans the .github/workflows directory of each configured repository, discovers every uses: reference, resolves the latest release of each action and can either report what is outdated (check) or pin every action to the latest release commit (update).

Why?

Pinning actions to a commit SHA is the recommended way to consume third-party GitHub Actions securely (to prevent version drift which can result in malicious code execution). But a plain SHA tells you nothing about which version it represents, and keeping it current by hand across several repositories is tedious. ADM automates this by rewriting references to the following form:

uses: actions/checkout@3d3c42e... # v7.0.1

The commit SHA is used as the actual pin, while the human-readable release tag is kept as a trailing comment.

Prerequisites

ADM relies on the GitHub CLI to look up release tags and their corresponding commit SHAs.

  • Go 1.26+ (to build/run from source)
  • gh CLI - installed and authenticated (gh auth login)
  • A GitHub account with access to the actions you depend on
Theorem (What ADM behind the scenes does)

To fetch the latest release version of an action, ADM uses the Github API to query the repository for its releases. It then retrieves the commit SHA associated with the latest release and rewrites the workflow file to pin the action to that specific commit SHA, while also adding a comment with the human-readable release tag for reference.

# Fetch the latest release tag of a dependency
gh release view --repo actions/checkout --json tagName --jq .tagName
 
# Resolve a tag (lightweight or annotated) to its commit SHA
gh api repos/actions/checkout/commits/v7.0.1 -H "Accept: application/vnd.github.sha"

Configuration

ADM reads a action-repositories.yaml file from the current working directory. Copy the provided example to get started:

cp action-repositories.yaml.example action-repositories.yaml

Here an overview of the fields in the configuration file:

FieldDescription
nameHuman-friendly name shown in the output.
idNumeric identifier used by the --select flag.
repoLocationAbsolute or relative path to the local checkout of the repository.

action-repositories.yaml is git-ignored, so your local paths stay private.

Example:

repos:
  - name: "Repo 1"
    id: 1
    repoLocation: "local/path/to/repo1"
  - name: "Repo 2"
    id: 2
    repoLocation: "local/path/to/repo2"

Usage

Run directly with Go:

go run main.go <command> [flags]

Or build a binary first:

go build -o adm .
./adm <command> [flags]