Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>flowpactNew to Visual Studio Code? Get it now.
flowpact

flowpact

Ruman Kazi

|
1 install
| (0) | Free
Diagnostics, hover traces and go to definition across GitHub Actions workflow calls: inputs, secrets, outputs and matrices checked as you type.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

flowpact for VS Code

flowpact checks the data flow between your GitHub Actions workflows: the inputs, secrets and outputs that cross reusable-workflow calls and local actions, per matrix combination. This extension runs it while you edit.

Features

  • Diagnostics as you type for the whole repository, closed files included. Editing a reusable workflow updates its callers' findings at once, before you save. Each finding links to its rule's documentation and shows the call chain that leads to it.
  • Hover an input, secret, output, env variable or matrix key to see how it is declared, where its value comes from and where it flows, through every level of nesting.
  • Go to definition across workflow calls and local actions: from with: config: to the callee's input, from needs.build.outputs.url to the reusable workflow's output, from steps.x.outputs.y to the action's output.
  • Find references and highlights across files.
  • Contract drift (FP801–FP805) as you edit, when the repository locks its contracts.

Your flowpact config applies as in the CLI and in CI: severities, overrides, ignores and plugins.

Requirements

VS Code 1.101 or later. The analysis is bundled; nothing else needs to be installed.

Settings

Setting Default Description
flowpact.plugins true Load the plugins the config lists. They run JavaScript from the repository, so they never load in an untrusted workspace.
flowpact.contracts auto Report contract drift: auto when .github/flowpact/contracts/ exists, on or off.
flowpact.overlappingRules auto FP502–FP505 repeat checks the GitHub Actions extension makes. auto hides them in files you open in the editor while that extension runs; show or hide them everywhere.
flowpact.hiddenRules [] Rule codes not to show in the editor.
flowpact.trace.server messages How much of each protocol message to show when the output's log level is Trace (messages or verbose).

Logs go to the flowpact output channel; its log level (Developer: Set Log Level…) also sets the server's.

Workspace trust

In Restricted Mode everything works except plugins. Trusting the workspace loads them without a restart. Plugins load only for repositories inside the workspace folders.

More

  • Editor documentation, including other editors (flowpact lsp)
  • Rules
  • Issues
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft