Shared GitHub Actions in the Claude Plugins Community Repository

The anthropics/claude-plugins-community repository maintains four reusable GitHub Actions—validate-plugins, scan-plugins, owner-liveness-sweep, and bump-plugin-shas—that centralize CI logic for plugin validation, security scanning, owner verification, and reproducible build management.

The Claude Plugins Community repository orchestrates continuous integration for a growing ecosystem of plugins through centralized automation. Rather than duplicating complex CI logic across multiple workflow files, the project encapsulates common operations into reusable composite actions stored in the .github/actions/ directory. This architecture ensures consistent validation, security enforcement, and maintenance operations across all plugin submissions while simplifying updates to shared CI logic.

Overview of the Shared GitHub Actions

The repository defines four distinct shared actions, each packaged in its own subdirectory under .github/actions/ with a standard action.yml metadata file. These actions are invoked by workflow definitions in .github/workflows/ using relative path references.

validate-plugins

The validate-plugins action runs a comprehensive suite of validation scripts that verify plugin manifests, enforce repository invariants, check auxiliary files, and ensure marketplace compliance. It serves as the primary quality gate for new plugin submissions and modifications.

Source: [.github/actions/validate-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)

Consumed by: [.github/workflows/validate-plugins.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml)

scan-plugins

The scan-plugins action performs static analysis to detect pin-check violations and enforce policy rules before merges complete. It specifically guards external pull requests against introducing unvetted dependencies or configuration drift.

Source: [.github/actions/scan-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml)

Consumed by: [.github/workflows/close-external-prs.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml)

owner-liveness-sweep

The owner-liveness-sweep action executes periodic verification to confirm plugin owners remain active. When it detects stale ownership, it triggers sweeps that can automatically close stale pull requests and flag dormant plugins for administrative review.

Source: [.github/actions/owner-liveness-sweep/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml)

Consumed by: [.github/workflows/owner-liveness-sweep.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml)

bump-plugin-shas

The bump-plugin-shas action maintains reproducible builds by updating the frozen SHA list (freeze-shas.txt) whenever a plugin's source changes. This ensures the repository's build matrix remains synchronized with verified plugin versions.

Source: [.github/actions/bump-plugin-shas/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)

Consumed by: [.github/workflows/bump-plugin-shas.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml)

Using Shared Actions in Workflows

Because these actions are defined locally within the repository, workflows reference them using relative paths with the ./ prefix. Below are implementation examples demonstrating how each action is invoked with its specific inputs.

Validating Plugin Changes

Trigger validation when plugin manifests or configuration files change:


# .github/workflows/validate-plugins.yml

name: Validate Plugins
on:
  push:
    paths:
      - '.github/plugins/**'
      - '*/.claude-plugin/**'
jobs:
  run-validation:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run shared validation
        uses: ./.github/actions/validate-plugins
        with:
          fail-fast: true

Scanning External Pull Requests

Enforce static pin-check policies before merging external contributions:


# .github/workflows/close-external-prs.yml

name: Scan Plugins before PR Merge
on:
  pull_request_target:
    types: [opened, reopened, synchronize]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run shared scan
        uses: ./.github/actions/scan-plugins
        with:
          policy: static-pin-check

Running Owner Liveness Checks

Schedule daily sweeps to verify maintainer activity:


# .github/workflows/owner-liveness-sweep.yml

name: Owner Liveness Sweep
on:
  schedule:
    - cron: '0 4 * * *'

jobs:
  sweep:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run owner-liveness sweep
        uses: ./.github/actions/owner-liveness-sweep

Updating Frozen SHAs

Automatically bump SHAs after successful validation completes:


# .github/workflows/bump-plugin-shas.yml

name: Bump Plugin SHAs
on:
  workflow_run:
    workflows: [Validate Plugins]
    types: [completed]

jobs:
  bump:
    runs-on: ubuntu-latest
    if: ${{ github.event.workflow_run.conclusion == 'success' }}
    steps:
      - uses: actions/checkout@v3
      - name: Update frozen SHAs
        uses: ./.github/actions/bump-plugin-shas
        with:
          sha-file: .github/freeze-shas.txt

Key Files and Implementation Details

Each shared action follows the GitHub Actions standard of defining its interface in action.yml, while complex logic is typically implemented in adjacent scripts within the action directory.

Action Metadata File Primary Workflow Consumer
validate-plugins [.github/actions/validate-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml) validate-plugins.yml
scan-plugins [.github/actions/scan-plugins/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml) close-external-prs.yml
owner-liveness-sweep [.github/actions/owner-liveness-sweep/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/owner-liveness-sweep/action.yml) owner-liveness-sweep.yml
bump-plugin-shas [.github/actions/bump-plugin-shas/action.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml) bump-plugin-shas.yml

When you modify any of these action.yml files, the changes immediately affect all workflows that reference them, providing a single source of truth for CI behavior across the repository.

Summary

  • The validate-plugins action provides centralized manifest validation and compliance checking for all plugin submissions.
  • The scan-plugins action enforces security policies and static analysis checks against external pull requests.
  • The owner-liveness-sweep action automates verification of maintainer activity and manages stale contribution lifecycle.
  • The bump-plugin-shas action maintains reproducible builds by synchronizing the freeze-shas.txt file with current plugin versions.
  • All four actions reside in .github/actions/ and are consumed by corresponding workflows in .github/workflows/ using relative path references.
  • Changes to shared actions propagate instantly to dependent workflows, ensuring consistent CI enforcement throughout the repository.

Frequently Asked Questions

How do I reference a shared action in a local workflow?

Workflows in the same repository reference shared actions using relative paths with the ./ prefix. For example, uses: ./.github/actions/validate-plugins points to the action defined in that directory's action.yml file. This local reference ensures the workflow always uses the version of the action committed in the current checkout.

What is the difference between validate-plugins and scan-plugins?

The validate-plugins action performs semantic validation of plugin manifests, checking for schema compliance, required auxiliary files, and marketplace readiness. The scan-plugins action focuses on security policy enforcement, specifically detecting static pin-check violations and other policy rules that could compromise repository integrity before merging external code.

How often does the owner-liveness-sweep run?

According to the workflow configuration in .github/workflows/owner-liveness-sweep.yml, the sweep runs on a scheduled cron trigger set to '0 4 * * *', which executes daily at 04:00 UTC. This schedule ensures regular verification of plugin owner activity without overwhelming the CI queue during peak development hours.

Can I use these actions in other repositories?

While these actions are designed for internal use within the claude-plugins-community repository, you can technically reuse them by copying the action directories to your own .github/actions/ path or by referencing them via repository path if the repository were public. However, they are tightly coupled to the specific validation scripts, policy files, and freeze-shas.txt structure of this repository, so external usage would require significant customization of the action logic.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →