如何通过GitHub API获取组织内GitHub Action的依赖仓库或使用情况
获取组织内GitHub Action的依赖仓库(Dependents)
GitHub目前没有官方API直接返回Insight > Dependencies > Dependents页面的内容,可通过以下替代方案实现:
- 使用GitHub GraphQL API进行搜索查询:通过搜索组织内所有Workflow文件中引用目标Action的仓库。核心思路是搜索
uses:组织名/Action仓库名的关键词,限定在.github/workflows/路径下。
示例GraphQL查询:
注意:该方法需处理分页(通过query FindActionDependents($org: String!, $actionRepo: String!) { search( query: "uses:${org}/${actionRepo} in:file path:.github/workflows/", type: REPOSITORY, first: 100 ) { nodes { ... on Repository { name owner { login } } } pageInfo { endCursor hasNextPage } } }pageInfo的endCursor和hasNextPage循环请求),且搜索结果可能存在少量遗漏,需结合实际场景验证。
获取组织内各仓库使用的所有GitHub Actions
可通过GitHub API结合Workflow内容解析实现,推荐两种方式:
方式1:REST API分步处理
- 第一步:调用
GET /orgs/{org}/repos获取组织内所有仓库(需处理分页)。 - 第二步:对每个仓库,调用
GET /repos/{owner}/{repo}/contents/.github/workflows获取所有Workflow文件路径。 - 第三步:对每个Workflow文件,调用
GET /repos/{owner}/{repo}/contents/{path}获取文件内容,解析YAML中的uses字段,提取对应的Action信息。
方式2:GraphQL API批量查询
通过GraphQL一次性获取组织内仓库的所有Workflow内容,再解析uses字段,效率更高:
示例GraphQL查询:
query GetOrgRepoActions($org: String!, $repoCursor: String) { organization(login: $org) { repositories(first: 100, after: $repoCursor) { nodes { name workflows(first: 100) { nodes { yaml } } } pageInfo { endCursor hasNextPage } } } }
- 解析注意事项:需处理YAML中嵌套结构的
uses(如jobs下的steps),同时区分官方Action(如actions/checkout@v4)、第三方Action和组织内部Action;若Workflow使用变量或矩阵语法,静态解析可能无法覆盖动态引用的场景,需根据需求补充处理逻辑。
内容的提问来源于stack exchange,提问作者semural
相关产品推荐
相关产品推荐

