Shared GitHub Actions in the Claude Plugins Community Repository
The anthropics/claude-plugins-community repository maintains four reusable GitHub Actions—validate-plugins, scan-plugins, owner-liveness-sweep, and bump-plugin-shas—that centralize CI logic for plugin validation, security scanning, owner verification, and reproducible build management.
The Claude Plugins Community repository orchestrates continuous integration for a growing ecosystem of plugins through centralized automation. Rather than duplicating complex CI logic across multiple workflow files, the project encapsulates common operations into reusable composite actions stored in the .github/actions/ directory. This architecture ensures consistent validation, security enforcement, and maintenance operations across all plugin submissions while simplifying updates to shared CI logic.
Overview of the Shared GitHub Actions
The repository defines four distinct shared actions, each packaged in its own subdirectory under .github/actions/ with a standard action.yml metadata file. These actions are invoked by workflow definitions in .github/workflows/ using relative path references.
validate-plugins
The validate-plugins action runs a comprehensive suite of validation scripts that verify plugin manifests, enforce repository invariants, check auxiliary files, and ensure marketplace compliance. It serves as the primary quality gate for new plugin submissions and modifications.
Source: [.github/actions/validate-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)
Consumed by: [.github/workflows/validate-plugins.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml)
scan-plugins
The scan-plugins action performs static analysis to detect pin-check violations and enforce policy rules before merges complete. It specifically guards external pull requests against introducing unvetted dependencies or configuration drift.
Source: [.github/actions/scan-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml)
Consumed by: [.github/workflows/close-external-prs.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml)
owner-liveness-sweep
The owner-liveness-sweep action executes periodic verification to confirm plugin owners remain active. When it detects stale ownership, it triggers sweeps that can automatically close stale pull requests and flag dormant plugins for administrative review.
Source: [.github/actions/owner-liveness-sweep/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml)
Consumed by: [.github/workflows/owner-liveness-sweep.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml)
bump-plugin-shas
The bump-plugin-shas action maintains reproducible builds by updating the frozen SHA list (freeze-shas.txt) whenever a plugin's source changes. This ensures the repository's build matrix remains synchronized with verified plugin versions.
Source: [.github/actions/bump-plugin-shas/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)
Consumed by: [.github/workflows/bump-plugin-shas.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml)
Using Shared Actions in Workflows
Because these actions are defined locally within the repository, workflows reference them using relative paths with the ./ prefix. Below are implementation examples demonstrating how each action is invoked with its specific inputs.
Validating Plugin Changes
Trigger validation when plugin manifests or configuration files change:
# .github/workflows/validate-plugins.yml
name: Validate Plugins
on:
push:
paths:
- '.github/plugins/**'
- '*/.claude-plugin/**'
jobs:
run-validation:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run shared validation
uses: ./.github/actions/validate-plugins
with:
fail-fast: true
Scanning External Pull Requests
Enforce static pin-check policies before merging external contributions:
# .github/workflows/close-external-prs.yml
name: Scan Plugins before PR Merge
on:
pull_request_target:
types: [opened, reopened, synchronize]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run shared scan
uses: ./.github/actions/scan-plugins
with:
policy: static-pin-check
Running Owner Liveness Checks
Schedule daily sweeps to verify maintainer activity:
# .github/workflows/owner-liveness-sweep.yml
name: Owner Liveness Sweep
on:
schedule:
- cron: '0 4 * * *'
jobs:
sweep:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run owner-liveness sweep
uses: ./.github/actions/owner-liveness-sweep
Updating Frozen SHAs
Automatically bump SHAs after successful validation completes:
# .github/workflows/bump-plugin-shas.yml
name: Bump Plugin SHAs
on:
workflow_run:
workflows: [Validate Plugins]
types: [completed]
jobs:
bump:
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.conclusion == 'success' }}
steps:
- uses: actions/checkout@v3
- name: Update frozen SHAs
uses: ./.github/actions/bump-plugin-shas
with:
sha-file: .github/freeze-shas.txt
Key Files and Implementation Details
Each shared action follows the GitHub Actions standard of defining its interface in action.yml, while complex logic is typically implemented in adjacent scripts within the action directory.
When you modify any of these action.yml files, the changes immediately affect all workflows that reference them, providing a single source of truth for CI behavior across the repository.
Summary
- The validate-plugins action provides centralized manifest validation and compliance checking for all plugin submissions.
- The scan-plugins action enforces security policies and static analysis checks against external pull requests.
- The owner-liveness-sweep action automates verification of maintainer activity and manages stale contribution lifecycle.
- The bump-plugin-shas action maintains reproducible builds by synchronizing the
freeze-shas.txtfile with current plugin versions. - All four actions reside in
.github/actions/and are consumed by corresponding workflows in.github/workflows/using relative path references. - Changes to shared actions propagate instantly to dependent workflows, ensuring consistent CI enforcement throughout the repository.
Frequently Asked Questions
How do I reference a shared action in a local workflow?
Workflows in the same repository reference shared actions using relative paths with the ./ prefix. For example, uses: ./.github/actions/validate-plugins points to the action defined in that directory's action.yml file. This local reference ensures the workflow always uses the version of the action committed in the current checkout.
What is the difference between validate-plugins and scan-plugins?
The validate-plugins action performs semantic validation of plugin manifests, checking for schema compliance, required auxiliary files, and marketplace readiness. The scan-plugins action focuses on security policy enforcement, specifically detecting static pin-check violations and other policy rules that could compromise repository integrity before merging external code.
How often does the owner-liveness-sweep run?
According to the workflow configuration in .github/workflows/owner-liveness-sweep.yml, the sweep runs on a scheduled cron trigger set to '0 4 * * *', which executes daily at 04:00 UTC. This schedule ensures regular verification of plugin owner activity without overwhelming the CI queue during peak development hours.
Can I use these actions in other repositories?
While these actions are designed for internal use within the claude-plugins-community repository, you can technically reuse them by copying the action directories to your own .github/actions/ path or by referencing them via repository path if the repository were public. However, they are tightly coupled to the specific validation scripts, policy files, and freeze-shas.txt structure of this repository, so external usage would require significant customization of the action logic.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →