Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>Nifty Actions: Workflow Checks, SHA Pinning & actNew to Visual Studio Code? Get it now.
Nifty Actions: Workflow Checks, SHA Pinning & act

Nifty Actions: Workflow Checks, SHA Pinning & act

Nifty

| (0) | Free
GitHub Actions workflows without sign-in: completion and go to definition for local and reusable actions, actionlint checks, pin actions to commit SHAs, and run jobs locally with act.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Nifty Actions: Workflow Checks, SHA Pinning & act

GitHub Actions workflows without sign-in: completion and go to definition for local and reusable actions, actionlint checks, pin actions to commit SHAs, and run jobs locally with act.

Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.

Everything works offline and without a GitHub account: completion, hovers, checks, go to definition and the outline read your repository's files. Only pinning, version checks and reading remote action.yml files call the GitHub API, anonymously unless you choose to sign in.

Features

Completing the inputs of the repository's own composite action under with:, with the description and default

Completing steps. in an expression: the ids of the steps that run before this one

Hovering a uses: line: where the action comes from, its inputs, and links to pin it or check for a newer version

Every action pinned to a commit SHA with the release as a comment

actionlint's error about a misspelled runner label in Problems, with its rule name

A team policy file blocking an action, flagged where the workflow uses it

Running a job locally with act from its CodeLens, in a terminal

Workflow language support

For .github/workflows/*.yml and action.yml files, whatever language mode they're in:

  • Completion of keys (workflow, on: events and their filters, jobs, steps, strategy, permissions, container, action.yml runs…), values (runner labels, shells, events, job ids for needs), and ./ paths of local actions and reusable workflows after uses:.
  • Inputs of what a step or job uses. Under with: you get the inputs of local composite actions, reusable workflows (uses: ./.github/workflows/x.yml) and remote actions (their action.yml is read from GitHub), with descriptions, defaults and required ones first. Reusable workflows also complete their secrets:.
  • ${{ }} expressions. Contexts and functions; steps. offers only steps with an id that run before the cursor; steps.<id>.outputs. offers the outputs of that step's action or the names its script writes to $GITHUB_OUTPUT; needs. offers the job's needs and needs.<job>.outputs. their outputs (including those of reusable workflows); matrix. offers matrix keys (also those only in include); inputs., env., secrets., github., runner.… if: values work without ${{ }}. Expressions are also highlighted in YAML.
  • Hovers for keys, contexts, functions, steps, jobs, inputs and outputs, and for uses: lines (the action's inputs and outputs, whether it's pinned, and links to pin it or check for a newer release).
  • Go to definition from uses: ./… to the local action or reusable workflow, from needs and needs.<job> to the job, from steps.<id> to the step, from outputs and with: inputs to where they're declared (also in other files), and from matrix.x and inputs.x to their keys.
  • Outline of triggers, inputs, jobs and steps (breadcrumbs and Go to Symbol too).

Checks

  • actionlint. actionlint checks workflow files as you type: expression types, runner labels, action inputs, cron syntax, and (with shellcheck and pyflakes installed) the scripts in run:. Problems show actionlint's rule name (runner-label, expression, shellcheck…) with a link to its docs. Use the actionlint on your PATH or set nifty.actions.actionlint.path, or run Nifty Actions: Download actionlint: it downloads a pinned release from rhysd/actionlint's GitHub releases only when you click, and checks it against the release's checksums file and the checksums built into the extension.
  • Quick checks when actionlint isn't there (and for action.yml files): YAML syntax, unknown keys, jobs without runs-on, needs that don't exist or loop, duplicate step ids, steps with both or neither of uses and run, expression syntax, unknown contexts and functions, steps/needs/matrix/inputs names that don't exist, missing local actions, and unknown or missing required inputs and secrets of local actions and reusable workflows. Checks that actionlint also does are skipped while it runs, so nothing is reported twice.
  • Suppress a problem on one line with the quick fix Ignore "rule" on this line, which adds # nifty-actions-ignore: rule (without a rule it hides everything on that line; alone on a line it applies to the next one). nifty.actions.ignoreRules hides a rule everywhere.

Pin actions to commit SHAs

A tag like @v4 can be moved to different code at any time, which is how the tj-actions/changed-files compromise in March 2025 reached thousands of repositories. Pinning to a full commit SHA stops that.

  • Actions that use a tag or branch are marked (a hint by default; see nifty.actions.pinning.unpinned). The quick fix, the hover link, Pin Action to Commit SHA, the "Pin N actions" CodeLens and Pin All Actions in This File rewrite uses: actions/checkout@v4 to uses: actions/checkout@<sha> # v4.2.2. A floating tag like v4 is named by the exact release on the same commit, quotes and other comment text are kept, and each owner/repo@ref is looked up once.
  • Pin All Actions in Workspace does every workflow and action.yml in the workspace and saves them.
  • Check for newer versions from the hover, or Update Actions to Latest Versions for the whole file: pinned actions are re-pinned to the new release's SHA, and tags move to the new one in the same style (v3 → v4).
  • Requests go to the GitHub REST API without a token. That allows 60 an hour; when they run out you're told when they reset and can choose to sign in with VS Code's built-in GitHub account (nifty.actions.github.signIn, 5,000 an hour and private repositories). For GitHub Enterprise Server set nifty.actions.github.apiUrl.

Team policy (.github/nifty-actions.json)

Create Action Policy File writes a starter policy listing the owners your workflows use. Violations show in Problems for everyone who opens the repository with Nifty Actions:

{
  "requirePinning": true,              // every remote action pinned to a full SHA…
  "pinningExceptions": ["actions/*"],  // …except these
  "allowed": ["actions/*", "github/*", "my-org/*", "docker/login-action@v3"],
  "blocked": ["tj-actions/changed-files"],
  "allowLocal": true,                  // ./ actions (default true)
  "allowDocker": true,                 // docker:// actions (default true)
  "severity": "error"                  // or warning, information, hint
}

Patterns work like GitHub's own "allowed actions" setting: owner/*, owner/repo, owner/repo@ref, owner/repo/path@*. The file has a JSON schema, so it completes and validates as you type.

Run jobs locally with act

With act installed, CodeLens above jobs: and each job runs the workflow or that job (Other event… picks the event). act runs in a terminal in your usual shell, so you see its colored output, can answer its first-run question and run the command again. List Jobs with act shows every job act finds and runs the one you pick. Extra arguments (-P images, --secret-file, --container-architecture) go in nifty.actions.act.args.

act runs each job in a container, so Docker must be running (Docker Desktop, Colima, or Podman with DOCKER_HOST set). Not every hosted-runner feature works locally; see act's documentation.

How it fits with other Nifty extensions

  • Nifty YAML formats any YAML (workflows included) without losing comments, runs yamllint and copies key paths. Nifty Actions adds what's specific to workflows: their keys, expressions, action references and checks. Use both.
  • Nifty JSON Schema validates workflow files against the SchemaStore schema. Nifty Actions goes further than a schema can: it knows which steps run before which, what inputs a local action has and whether a job id exists.
  • Nifty Dependency Guard checks npm and pip dependencies. Nifty Actions covers the other supply chain in a repository: the actions your CI runs.
  • Nifty Run runs your project's scripts and tasks; Nifty Actions runs its CI jobs with act.

In the browser

On vscode.dev and github.dev, completion, hovers, go to definition, the outline, quick checks, the policy file, pinning and version checks all work. actionlint and act need a local program, so they're desktop only.

Commands

Command What it does
Nifty Actions: Pin Action to Commit SHA Pin the uses: on the cursor line
Nifty Actions: Pin All Actions in This File Pin every action in the file
Nifty Actions: Pin All Actions in Workspace Pin every workflow and action.yml, and save them
Nifty Actions: Check for a Newer Version of This Action Look up the latest release of the action on the cursor line
Nifty Actions: Update Actions to Latest Versions Pick outdated actions in the file and update them
Nifty Actions: Create Action Policy File Create or open .github/nifty-actions.json
Nifty Actions: Check All Workflows Check every workflow and action.yml into Problems
Nifty Actions: Use GitHub Sign-in for API Requests Use VS Code's GitHub account for pinning and version checks
Nifty Actions: Download actionlint Download and verify actionlint (desktop)
Nifty Actions: Show actionlint Location Which actionlint is used, and its version (desktop)
Nifty Actions: Run Job with act Run the job at the cursor (or pick one) with act (desktop)
Nifty Actions: Run Workflow with act Run the whole workflow with act (desktop)
Nifty Actions: List Jobs with act act -l, then run the job you pick (desktop)
Nifty Actions: Show Log Requests, pins and tool runs

Settings

Setting Default What it does
nifty.actions.actionlint.enabled true Check workflows with actionlint when it's available
nifty.actions.actionlint.path actionlint executable (else the downloaded copy, then PATH)
nifty.actions.actionlint.run onType onType or onSave
nifty.actions.actionlint.shellcheck true Let actionlint run shellcheck on run: scripts
nifty.actions.actionlint.pyflakes true Let actionlint run pyflakes on Python scripts
nifty.actions.actionlint.ignore [] Regular expressions of messages to ignore (-ignore)
nifty.actions.actionlint.args [] Extra actionlint arguments, e.g. -config-file
nifty.actions.actionlint.downloadUrl GitHub releases Where Download actionlint gets releases (a mirror works too)
nifty.actions.quickChecks.enabled true Nifty's own checks
nifty.actions.ignoreRules [] Rule ids to hide everywhere
nifty.actions.pinning.unpinned hint How to mark unpinned actions: off, hint, information, warning, error
nifty.actions.pinning.trusted [] Actions that don't need pinning, e.g. my-org/*
nifty.actions.pinning.codeLens true The "Pin N actions" CodeLens
nifty.actions.github.apiUrl https://api.github.com REST API (GitHub Enterprise Server: https://HOST/api/v3)
nifty.actions.github.signIn false Use VS Code's GitHub account for API requests
nifty.actions.remoteActions.fetch true Read remote action.yml files for input completion and checks
nifty.actions.versions.checkOnHover false Look up newer releases when hovering uses:
nifty.actions.policy.enabled true Check actions against .github/nifty-actions.json
nifty.actions.act.path act executable (else PATH)
nifty.actions.act.args [] Extra arguments for act runs
nifty.actions.act.codeLens true "Run job with act" CodeLens

GitHub and GitHub Actions are trademarks of GitHub, Inc. Nifty Actions is an independent project; it isn't affiliated with or endorsed by GitHub. It works with actionlint (MIT, by rhysd) and act (MIT, by nektos), which it runs but doesn't bundle.

Install

  • VS Code: search for "Nifty Actions" in the Extensions view, or install from the Visual Studio Marketplace.
  • Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.

Privacy

This extension collects no telemetry and needs no account. It contacts GitHub only to pin actions, check versions, read the action.yml of remote actions (turn off with nifty.actions.remoteActions.fetch) and, when you ask, download actionlint. Requests are anonymous unless you turn on nifty.actions.github.signIn.

More Nifty tools

  • Nifty YAML: Formatter, Validator & Converter: Format YAML without losing comments (Kubernetes-style indents), sort keys, lint with yamllint, copy the key path, and convert to and from JSON. (Open VSX)
  • Nifty JSON Schema: Validate with Draft 2020-12 & 2019-09: Validate JSON, JSONC and YAML against JSON Schema 2020-12, 2019-09, draft-07, 06 and 04, with precise errors, hover, completion, SchemaStore lookup and schema generation. (Open VSX)
  • Nifty OpenAPI: Outline, Checks and Try It for API Specs: Edit OpenAPI and Swagger files with an outline, $ref navigation and completion, error checking, example payloads, and Try it requests for your REST client. (Open VSX)
  • Nifty Dependency Guard: Package Security Check: Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt. (Open VSX)
  • Nifty HCL Tools: .tf and .hcl Language Support: Fast, lightweight Terraform and OpenTofu support: highlighting, outline, go to definition and references across a module, hovers, completion, undefined-reference errors and formatting. (Open VSX)
  • Nifty Helm & Kustomize: Values IntelliSense: Helm .Values IntelliSense (completion, hover, go to definition, missing values) and Kustomize navigation, checks with quick fixes, an overlay tree, patch target hovers, build previews and diffs. (Open VSX)

See all 100+ Nifty extensions and web tools at https://getnifty.dev

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft