Support for GitHub Actions in Dependency Graph

GitHub has its own package ecosystem:

It has a package format action.yml (or action.yaml):

And a dependency format .github/workflows/*.yml (or .github/workflows/*.yaml):

Has any consideration been made to adding this ecosystem to the supported set in:

Composer PHP composer.lock composer.json, composer.lock
dotnet CLI .NET languages (C#, C++, F#, VB) .csproj, .vbproj, .nuspec, .vcxproj, .fsproj .csproj, .vbproj, .nuspec, .vcxproj, .fsproj, packages.config
Maven Java, Scala pom.xml pom.xml
npm JavaScript package-lock.json package-lock.json, package.json
Python PIP Python requirements.txt, pipfile.lock requirements.txt, pipfile, pipfile.lock, setup.py*
RubyGems Ruby Gemfile.lock Gemfile.lock, Gemfile, *.gemspec
Yarn JavaScript yarn.lock package.json, yarn.lock

It’d be really helpful for action developers who don’t use a subscription model.

3 Likes