# Shared GitHub Actions in the Claude Plugins Community Repository

> Explore four shared GitHub Actions in the claude-plugins-community repo: validate-plugins, scan-plugins, owner-liveness-sweep, and bump-plugin-shas. Streamline your CI workflows.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: how-to-guide
- Published: 2026-08-28

---

**The `anthropics/claude-plugins-community` repository maintains four reusable GitHub Actions—`validate-plugins`, `scan-plugins`, `owner-liveness-sweep`, and `bump-plugin-shas`—that centralize CI logic for plugin validation, security scanning, owner verification, and reproducible build management.**

The Claude Plugins Community repository orchestrates continuous integration for a growing ecosystem of plugins through centralized automation. Rather than duplicating complex CI logic across multiple workflow files, the project encapsulates common operations into reusable composite actions stored in the `.github/actions/` directory. This architecture ensures consistent validation, security enforcement, and maintenance operations across all plugin submissions while simplifying updates to shared CI logic.

## Overview of the Shared GitHub Actions

The repository defines four distinct shared actions, each packaged in its own subdirectory under `.github/actions/` with a standard [`action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/action.yml) metadata file. These actions are invoked by workflow definitions in `.github/workflows/` using relative path references.

### validate-plugins

The **`validate-plugins`** action runs a comprehensive suite of validation scripts that verify plugin manifests, enforce repository invariants, check auxiliary files, and ensure marketplace compliance. It serves as the primary quality gate for new plugin submissions and modifications.

**Source:** [[`.github/actions/validate-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)

**Consumed by:** [[`.github/workflows/validate-plugins.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml)

### scan-plugins

The **`scan-plugins`** action performs static analysis to detect pin-check violations and enforce policy rules before merges complete. It specifically guards external pull requests against introducing unvetted dependencies or configuration drift.

**Source:** [[`.github/actions/scan-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml)

**Consumed by:** [[`.github/workflows/close-external-prs.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml)

### owner-liveness-sweep

The **`owner-liveness-sweep`** action executes periodic verification to confirm plugin owners remain active. When it detects stale ownership, it triggers sweeps that can automatically close stale pull requests and flag dormant plugins for administrative review.

**Source:** [[`.github/actions/owner-liveness-sweep/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml)

**Consumed by:** [[`.github/workflows/owner-liveness-sweep.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml)

### bump-plugin-shas

The **`bump-plugin-shas`** action maintains reproducible builds by updating the frozen SHA list ([`freeze-shas.txt`](https://github.com/anthropics/claude-plugins-community/blob/main/freeze-shas.txt)) whenever a plugin's source changes. This ensures the repository's build matrix remains synchronized with verified plugin versions.

**Source:** [[`.github/actions/bump-plugin-shas/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)

**Consumed by:** [[`.github/workflows/bump-plugin-shas.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml)

## Using Shared Actions in Workflows

Because these actions are defined locally within the repository, workflows reference them using relative paths with the `./` prefix. Below are implementation examples demonstrating how each action is invoked with its specific inputs.

### Validating Plugin Changes

Trigger validation when plugin manifests or configuration files change:

```yaml

# .github/workflows/validate-plugins.yml

name: Validate Plugins
on:
  push:
    paths:
      - '.github/plugins/**'
      - '*/.claude-plugin/**'
jobs:
  run-validation:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run shared validation
        uses: ./.github/actions/validate-plugins
        with:
          fail-fast: true

```

### Scanning External Pull Requests

Enforce static pin-check policies before merging external contributions:

```yaml

# .github/workflows/close-external-prs.yml

name: Scan Plugins before PR Merge
on:
  pull_request_target:
    types: [opened, reopened, synchronize]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run shared scan
        uses: ./.github/actions/scan-plugins
        with:
          policy: static-pin-check

```

### Running Owner Liveness Checks

Schedule daily sweeps to verify maintainer activity:

```yaml

# .github/workflows/owner-liveness-sweep.yml

name: Owner Liveness Sweep
on:
  schedule:
    - cron: '0 4 * * *'

jobs:
  sweep:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run owner-liveness sweep
        uses: ./.github/actions/owner-liveness-sweep

```

### Updating Frozen SHAs

Automatically bump SHAs after successful validation completes:

```yaml

# .github/workflows/bump-plugin-shas.yml

name: Bump Plugin SHAs
on:
  workflow_run:
    workflows: [Validate Plugins]
    types: [completed]

jobs:
  bump:
    runs-on: ubuntu-latest
    if: ${{ github.event.workflow_run.conclusion == 'success' }}
    steps:
      - uses: actions/checkout@v3
      - name: Update frozen SHAs
        uses: ./.github/actions/bump-plugin-shas
        with:
          sha-file: .github/freeze-shas.txt

```

## Key Files and Implementation Details

Each shared action follows the GitHub Actions standard of defining its interface in [`action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/action.yml), while complex logic is typically implemented in adjacent scripts within the action directory.

| Action | Metadata File | Primary Workflow Consumer |
|--------|---------------|---------------------------|
| **validate-plugins** | [[`.github/actions/validate-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml) | [`validate-plugins.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/validate-plugins.yml) |
| **scan-plugins** | [[`.github/actions/scan-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml) | [`close-external-prs.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/close-external-prs.yml) |
| **owner-liveness-sweep** | [[`.github/actions/owner-liveness-sweep/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml) | [`owner-liveness-sweep.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/owner-liveness-sweep.yml) |
| **bump-plugin-shas** | [[`.github/actions/bump-plugin-shas/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml) | [`bump-plugin-shas.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/bump-plugin-shas.yml) |

When you modify any of these [`action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/action.yml) files, the changes immediately affect all workflows that reference them, providing a single source of truth for CI behavior across the repository.

## Summary

- The **validate-plugins** action provides centralized manifest validation and compliance checking for all plugin submissions.
- The **scan-plugins** action enforces security policies and static analysis checks against external pull requests.
- The **owner-liveness-sweep** action automates verification of maintainer activity and manages stale contribution lifecycle.
- The **bump-plugin-shas** action maintains reproducible builds by synchronizing the [`freeze-shas.txt`](https://github.com/anthropics/claude-plugins-community/blob/main/freeze-shas.txt) file with current plugin versions.
- All four actions reside in `.github/actions/` and are consumed by corresponding workflows in `.github/workflows/` using relative path references.
- Changes to shared actions propagate instantly to dependent workflows, ensuring consistent CI enforcement throughout the repository.

## Frequently Asked Questions

### How do I reference a shared action in a local workflow?

Workflows in the same repository reference shared actions using relative paths with the `./` prefix. For example, `uses: ./.github/actions/validate-plugins` points to the action defined in that directory's [`action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/action.yml) file. This local reference ensures the workflow always uses the version of the action committed in the current checkout.

### What is the difference between validate-plugins and scan-plugins?

The **validate-plugins** action performs semantic validation of plugin manifests, checking for schema compliance, required auxiliary files, and marketplace readiness. The **scan-plugins** action focuses on security policy enforcement, specifically detecting static pin-check violations and other policy rules that could compromise repository integrity before merging external code.

### How often does the owner-liveness-sweep run?

According to the workflow configuration in [`.github/workflows/owner-liveness-sweep.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml), the sweep runs on a scheduled cron trigger set to `'0 4 * * *'`, which executes daily at 04:00 UTC. This schedule ensures regular verification of plugin owner activity without overwhelming the CI queue during peak development hours.

### Can I use these actions in other repositories?

While these actions are designed for internal use within the `claude-plugins-community` repository, you can technically reuse them by copying the action directories to your own `.github/actions/` path or by referencing them via repository path if the repository were public. However, they are tightly coupled to the specific validation scripts, policy files, and [`freeze-shas.txt`](https://github.com/anthropics/claude-plugins-community/blob/main/freeze-shas.txt) structure of this repository, so external usage would require significant customization of the action logic.