{"id":26493758,"url":"https://github.com/gacts/github-slug","last_synced_at":"2025-10-06T02:58:56.724Z","repository":{"id":39708659,"uuid":"408453202","full_name":"gacts/github-slug","owner":"gacts","description":"🚀 GitHub Action to expose slug values of branch/tag/version inside your GitHub workflow","archived":false,"fork":false,"pushed_at":"2025-10-02T00:24:41.000Z","size":1659,"stargazers_count":8,"open_issues_count":1,"forks_count":1,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-10-02T02:37:43.927Z","etag":null,"topics":["action","github-actions","slug"],"latest_commit_sha":null,"homepage":"https://github.com/marketplace/actions/github-slug","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gacts.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-09-20T13:25:24.000Z","updated_at":"2025-10-02T00:24:45.000Z","dependencies_parsed_at":"2023-02-17T04:02:27.586Z","dependency_job_id":"2fb88f8f-baf4-4158-b25f-e33905b7eec2","html_url":"https://github.com/gacts/github-slug","commit_stats":{"total_commits":95,"total_committers":2,"mean_commits":47.5,"dds":"0.41052631578947374","last_synced_commit":"b648ab06c348186877895d0d15ae7042cc56a856"},"previous_names":[],"tags_count":18,"template":false,"template_full_name":"actions/javascript-action","purl":"pkg:github/gacts/github-slug","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gacts%2Fgithub-slug","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gacts%2Fgithub-slug/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gacts%2Fgithub-slug/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gacts%2Fgithub-slug/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gacts","download_url":"https://codeload.github.com/gacts/github-slug/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gacts%2Fgithub-slug/sbom","scorecard":{"id":416817,"data":{"date":"2025-08-11","repo":{"name":"github.com/gacts/github-slug","commit":"ac653a09c7a4b67cdff01a0ba7da112ac41bfaa2"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/24 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":4,"reason":"5 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 4","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/test.yml:58","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/gacts/github-slug/test.yml/master?enable=pin","Warn: npmCommand not pinned by hash: .github/workflows/test.yml:35","Warn: npmCommand not pinned by hash: .github/workflows/test.yml:46","Info:   0 out of  10 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   3 third-party GitHubAction dependencies pinned","Info:   0 out of   2 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 21 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-19T00:08:28.125Z","repository_id":39708659,"created_at":"2025-08-19T00:08:28.125Z","updated_at":"2025-08-19T00:08:28.125Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278551509,"owners_count":26005389,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-06T02:00:05.630Z","response_time":65,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["action","github-actions","slug"],"created_at":"2025-03-20T09:57:08.826Z","updated_at":"2025-10-06T02:58:56.709Z","avatar_url":"https://github.com/gacts.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://avatars0.githubusercontent.com/u/44036562?s=200\u0026v=4\" alt=\"Logo\" width=\"100\" /\u003e\n\u003c/p\u003e\n\n# GitHub slug action\n\n![Release version][badge_release_version]\n[![Build Status][badge_build]][link_build]\n[![License][badge_license]][link_license]\n\nGitHub Action to expose slug values of branches, tags, or versions inside your GitHub workflow.\n\n## Overview\n\nA slug applied to a variable will:\n\n- Convert the variable content to **lowercase**\n- Replace special characters like `$` or `%` with `dollar` and `percent`, respectively\n- Replace any character except `0-9`, `a-z`, and `-` with `-`\n- Remove leading, trailing, and duplicated `-` characters\n\n## Usage\n\nAdd this in your workflow:\n\n```yaml\njobs:\n  - uses: gacts/github-slug@v1\n    id: slug\n    with:\n      to-slug: Hello ${{ github.actor }}! How are you? # feel free to use any variable or string here\n```\n\nIn subsequent steps, you will be able to use the following variables:\n\n| Description                                     | How to use in your workflow                   | Examples for `branch`/`tag` workflows      |\n|-------------------------------------------------|-----------------------------------------------|--------------------------------------------|\n| A slugged version of \"to-slug\" input            | `${{ steps.slug.outputs.slug }}`              | `hello-username-how-are-you`               |\n| The workflow was triggered on a branch          | `${{ steps.slug.outputs.is-branch }}`         | `true`/`false`                             |\n| The workflow was triggered on a tag             | `${{ steps.slug.outputs.is-tag }}`            | `false`/`true`                             |\n| Current branch name                             | `${{ steps.slug.outputs.branch-name }}`       | `fix/Foo_bar`/`\u003cempty-value\u003e`              |\n| A slugged version of `branch-name`              | `${{ steps.slug.outputs.branch-name-slug }}`  | `fix-foo-bar`/`\u003cempty-value\u003e`              |\n| Current tag name                                | `${{ steps.slug.outputs.tag-name }}`          | `\u003cempty-value\u003e`/`v1.2-rc1_Lorem`           |\n| A slugged version of `tag-name`                 | `${{ steps.slug.outputs.tag-name-slug }}`     | `\u003cempty-value\u003e`/`v1-2-rc1-lorem`           |\n| The commit SHA hash that triggered the workflow | `${{ steps.slug.outputs.commit-hash }}`       | `ffac537e6cbbf934b08745a378932722df287a53` |\n| Short _(7 first characters)_ commit SHA hash    | `${{ steps.slug.outputs.commit-hash-short }}` | `ffac537`                                  |\n| Cleared and slugged version value \u003csup\u003e*\u003c/sup\u003e  | `${{ steps.slug.outputs.version }}`           | `fix-foo-bar`/`1.2-rc1-lorem`              |\n| Major version                                   | `${{ steps.slug.outputs.version-major }}`     | `0`/`1`                                    |\n| Minor version                                   | `${{ steps.slug.outputs.version-minor }}`     | `0`/`2`                                    |\n| Patch version                                   | `${{ steps.slug.outputs.version-patch }}`     | `0`/`0`                                    |\n| Semantic version value                          | `${{ steps.slug.outputs.version-semantic }}`  | `0.0.0-fix-foo-bar`/`1.2.0-rc1-lorem`      |\n\n\u003e \u003csup\u003e*\u003c/sup\u003e A prefix `v/ver/version[._-]` will be removed\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003cstrong\u003eUsage examples\u003c/strong\u003e\u003c/summary\u003e\n\n### On a branch:\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://hsto.org/webt/ah/qe/_e/ahqe_e03-tvp-whxpn0g6_q_vo8.png\" alt=\"on the branch\" /\u003e\n\u003c/p\u003e\n\n```yaml\nname: tests\n\non:\n  push:\n    branches: [master, main]\n    paths-ignore: ['**.md']\n    tags-ignore: ['**']\n  pull_request:\n    paths-ignore: ['**.md']\n\njobs:\n  build:\n    name: Build for ${{ matrix.os }} (${{ matrix.arch }})\n    runs-on: ubuntu-latest\n    strategy:\n      fail-fast: false\n      matrix:\n        os: [linux, darwin]\n        arch: [amd64]\n    steps:\n      - name: Set up Go\n        uses: actions/setup-go@v5\n        with: {go-version: 1.22}\n\n      - name: Check out code\n        uses: actions/checkout@v4\n\n      - uses: gacts/github-slug@v1\n        id: slug\n\n      - name: Build application\n        env:\n          GOOS: ${{ matrix.os }}\n          GOARCH: ${{ matrix.arch }}\n          CGO_ENABLED: 0\n          LDFLAGS: -s -w -X internal/pkg/version.version=${{ steps.slug.outputs.branch-name-slug }}@${{ steps.slug.outputs.commit-hash-short }}\n        run: go build -trimpath -ldflags \"$LDFLAGS\" -o ./app ./cmd/app/\n```\n\n### On a tag:\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://hsto.org/webt/y7/pl/ov/y7plovzqsmgjafdbwncrlysiaqm.png\" alt=\"on the tag\" /\u003e\n\u003c/p\u003e\n\n```yaml\nname: release\n\non:\n  release: # Docs: \u003chttps://help.github.com/en/articles/events-that-trigger-workflows#release-event-release\u003e\n    types: [published]\n\njobs:\n  docker-image:\n    name: Build the docker image\n    runs-on: ubuntu-latest\n    steps:\n      - name: Check out code\n        uses: actions/checkout@v4\n\n      - uses: gacts/github-slug@v1\n        id: slug\n\n      - name: Login to GitHub Container Registry\n        uses: docker/login-action@v3 # Action page: \u003chttps://github.com/docker/login-action\u003e\n        with:\n          registry: ghcr.io\n          username: ${{ github.actor }}\n          password: ${{ secrets.GHCR_PASSWORD }} # PAT token, generate new: \u003chttps://github.com/settings/tokens/new\u003e\n\n      - uses: docker/build-push-action@v6 # Action page: \u003chttps://github.com/docker/build-push-action\u003e\n        with:\n          context: .\n          file: Dockerfile\n          push: true\n          tags: |\n            ghcr.io/${{ github.actor }}/${{ github.event.repository.name }}:${{ steps.slug.outputs.version }}\n            ghcr.io/${{ github.actor }}/${{ github.event.repository.name }}:latest\n```\n\n\u003c/details\u003e\n\n## Releasing\n\nTo release a new version:\n\n- Build the action distribution (`make build` or `npm run build`).\n- Commit and push changes (including `dist` directory changes - this is important) to the `master|main` branch.\n- Publish the new release using the repo releases page (the git tag should follow the `vX.Y.Z` format).\n\nMajor and minor git tags (`v1` and `v1.2` if you publish a `v1.2.Z` release) will be updated automatically.\n\n\u003e [!TIP]\n\u003e Use [Dependabot](https://bit.ly/45zwLL1) to keep this action updated in your repository.\n\n## Support\n\n[![Issues][badge_issues]][link_issues]\n[![Pull Requests][badge_pulls]][link_pulls]\n\nIf you find any errors in the action, please [create an issue][link_create_issue] in this repository.\n\n## License\n\nThis is open-source software licensed under the [MIT License][link_license].\n\n[badge_build]:https://img.shields.io/github/actions/workflow/status/gacts/github-slug/test.yml?branch=master\u0026maxAge=30\n[badge_release_version]:https://img.shields.io/github/release/gacts/github-slug.svg?maxAge=30\n[badge_license]:https://img.shields.io/github/license/gacts/github-slug.svg?longCache=true\n[badge_release_date]:https://img.shields.io/github/release-date/gacts/github-slug.svg?maxAge=180\n[badge_commits_since_release]:https://img.shields.io/github/commits-since/gacts/github-slug/latest.svg?maxAge=45\n[badge_issues]:https://img.shields.io/github/issues/gacts/github-slug.svg?maxAge=45\n[badge_pulls]:https://img.shields.io/github/issues-pr/gacts/github-slug.svg?maxAge=45\n\n[link_build]:https://github.com/gacts/github-slug/actions\n[link_license]:https://github.com/gacts/github-slug/blob/master/LICENSE\n[link_issues]:https://github.com/gacts/github-slug/issues\n[link_create_issue]:https://github.com/gacts/github-slug/issues/new\n[link_pulls]:https://github.com/gacts/github-slug/pulls\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgacts%2Fgithub-slug","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgacts%2Fgithub-slug","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgacts%2Fgithub-slug/lists"}