{"id":21969460,"url":"https://github.com/rnett/kotlin-js-action","last_synced_at":"2026-03-03T09:31:29.555Z","repository":{"id":57722436,"uuid":"338472474","full_name":"rnett/kotlin-js-action","owner":"rnett","description":"Kotlin JS SDK for writing GitHub Actions","archived":false,"fork":false,"pushed_at":"2022-11-23T06:27:25.000Z","size":8889,"stargazers_count":16,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-28T00:58:45.148Z","etag":null,"topics":["actions","github-actions","kotlin","kotlin-js"],"latest_commit_sha":null,"homepage":"https://rnett.github.io/kotlin-js-action/","language":"Kotlin","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rnett.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null}},"created_at":"2021-02-13T01:21:37.000Z","updated_at":"2024-10-23T15:48:48.000Z","dependencies_parsed_at":"2023-01-23T16:00:26.588Z","dependency_job_id":null,"html_url":"https://github.com/rnett/kotlin-js-action","commit_stats":null,"previous_names":[],"tags_count":7,"template":false,"template_full_name":null,"purl":"pkg:github/rnett/kotlin-js-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rnett%2Fkotlin-js-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rnett%2Fkotlin-js-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rnett%2Fkotlin-js-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rnett%2Fkotlin-js-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rnett","download_url":"https://codeload.github.com/rnett/kotlin-js-action/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rnett%2Fkotlin-js-action/sbom","scorecard":{"id":779384,"data":{"date":"2025-08-11","repo":{"name":"github.com/rnett/kotlin-js-action","commit":"3b3746522c485f265e53422be5777e53ce536a7d"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.6,"checks":[{"name":"Code-Review","score":0,"reason":"Found 1/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":8,"reason":"binaries present in source code","details":["Warn: binary detected: kotlin-js-action/gradle/wrapper/gradle-wrapper.jar:1","Warn: binary detected: test-action/gradle/wrapper/gradle-wrapper.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:249: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:256: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:205: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:222: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:229: update your workflow using https://app.stepsecurity.io/secureworkflow/rnett/kotlin-js-action/ci.yml/main?enable=pin","Info:   0 out of   9 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  10 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 11 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"39 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-76p7-773f-r4q5","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3","Warn: Project is vulnerable to: GHSA-776f-qx25-q3cc","Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7","Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-r7qp-cfhv-p84w","Warn: Project is vulnerable to: GHSA-q9mw-68c2-j6m5","Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc","Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx","Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc","Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp","Warn: Project is vulnerable to: GHSA-c7qv-q95q-8v27","Warn: Project is vulnerable to: GHSA-4www-5p9h-95mh","Warn: Project is vulnerable to: GHSA-9gqv-wp59-fq42","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j","Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w","Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg","Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p","Warn: Project is vulnerable to: GHSA-25hc-qcg6-38wj","Warn: Project is vulnerable to: GHSA-cqmj-92xf-r6r9","Warn: Project is vulnerable to: GHSA-fhg7-m89q-25r3","Warn: Project is vulnerable to: GHSA-hc6q-2mpp-qw7j","Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986","Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6","Warn: Project is vulnerable to: GHSA-4v9v-hfq4-rm2v","Warn: Project is vulnerable to: GHSA-9jgg-88mc-972h","Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T04:32:17.921Z","repository_id":57722436,"created_at":"2025-08-23T04:32:17.921Z","updated_at":"2025-08-23T04:32:17.921Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30039884,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-03T06:58:30.252Z","status":"ssl_error","status_checked_at":"2026-03-03T06:58:15.329Z","response_time":61,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["actions","github-actions","kotlin","kotlin-js"],"created_at":"2024-11-29T14:20:46.205Z","updated_at":"2026-03-03T09:31:29.523Z","avatar_url":"https://github.com/rnett.png","language":"Kotlin","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Kotlin JS GitHub Action SDK\n\n[![Maven Central](https://img.shields.io/maven-central/v/com.github.rnett.ktjs-github-action/kotlin-js-action)](https://search.maven.org/artifact/com.github.rnett.ktjs-github-action/kotlin-js-action)\n[![Sonatype Nexus (Snapshots)](https://img.shields.io/nexus/s/com.github.rnett.ktjs-github-action/kotlin-js-action?server=https%3A%2F%2Foss.sonatype.org)](https://oss.sonatype.org/content/repositories/snapshots/com/github/rnett/ktjs-github-action/)\n[![GitHub Repo](https://img.shields.io/badge/GitHub-kotlin--js--action-blue?logo=github)](https://github.com/rnett/kotlin-js-action)\n[![License](https://img.shields.io/badge/License-Apache%202.0-yellowgreen.svg)](https://opensource.org/licenses/Apache-2.0)\n[![Changelog](https://img.shields.io/badge/Changelog-CHANGELOG.md-green)](./CHANGELOG.md#changelog)\n\n### Artifacts\n\n* `com.github.rnett.ktjs-github-action:kotlin-js-action` - the SDK\n* `com.github.rnett.ktjs-github-action:serialization` - Kotlinx serialization support for the SDK\n* `com.github.rnett.ktjs-github-action` - a gradle plugin for building GitHub Actions. The maven artifact\n  is `com.github.rnett.ktjs-github-action:kotlin-js-action-plugin`\n  if you are not using the `plugins` block.\n\nUsing the IR backend is required.\n\n### [Docs](https://rnett.github.io/kotlin-js-action/release/)\n\n[For latest SNAPSHOT build](https://rnett.github.io/kotlin-js-action/snapshot/)\n\nKotlin JS utilities for writing GitHub Actions, including wrappers\nfor [actions/toolkit](https://github.com/actions/toolkit) packages, except for `@actions/github`\nand `@actions/tool-cache`.  `@actions/tool-cache` will be added once blocking `dukat` bugs are fixes.\n\n## SDK\n\nThe GitHub actions SDK provides wrappers for most of the [`actions/toolkit`](https://github.com/actions/toolkit)\npackages, as well as some utilities for working with NodeJS types.\n\nActions should almost always have an entrypoint like:\n\n```kotlin\nsuspend fun main() = runAction {\n\n}\n```\n\nThis ensures that any uncaught exceptions are properly reported to the GitHub runtime.\n\nGenerally, most of the wrappers are thin and can be fully understood by reading the docs. We explain the more\ncomplicated ones below.\n\n### Utils\n\nUtilities include backpressure cognizant `Flow` \u003c-\u003e `Stream` conversions,\n`WritableStream.writeSuspending` (which suspend for backpressure),\n`Buffer.asByteArray()`, `jsEntries`, and an `external interface` object builder `JsObject`.\n\n### Inputs, State, and Env\n\nThe `inputs`, `state`, and `env` (and `exportEnv`) objects provide action input, state, and environment accessors. They\ncan all be accessed by key, but also provide delegates. Delegates can delegate from the object directly, specify a name\nwith `invoke(String)`, or whether the value is required with `optional`/`optional(String)` and `required`\n/`required(String)`.\n`inputs` and `state` delegates are required by default and the objects have `optional` versions, where `env` is the\nopposite.\n\n`exportEnv`/`env.export` is another environment wrapper that exports set environment variables to the GitHub workflow.\n\n### Typesafe delegates\n\nMany objects, including `inputs`, `env`, and `outputs`, are accessed primarily by `String` delegates. However, this is\ninsufficient when accessing structured data, such as multi-line or boolean inputs or JSON formatted `state`.\n\nTo this end, we provide delegate (`ReadOnlyProperty` and `ReadWriteProperty`, to be exact) mapping functions in\nthe `delegates` package. You can write your own using `map`, `mapNonNull`, `ifNull`, etc, and we provide a large set of\ndefault implementations including `isTrue` (\\~`toBoolean` in the stdlib),\n`toBoolean` (\\~`toBooleanStrict` in the stdlib), `toInt`, `lines`, `trim`, and `lowercase` for both read-only and\nread-write delegates.\n\nThis is also how serialization support is implemented. The `serialization` artifact provides `deserialize`\nand `serialize` methods, so you can do something like `val myState by state.deserialize\u003cMyState\u003e()`.\n\n### Shell Exec\n\n`exec` is based on the `@actions/exec` package, however it has some issues with input redirection, in particular that\npassing `outStream` will cause a `[command] $command` header to be written to the output file. To this end we provide\n`execShell` commands that instead of executing the raw command, excuting it using something like `bash -c \"$command\"`.\nPowershell (Windows) or bash are used by default. Note that powershell output redirects (`\u003e`) will be written in\nUTF-16-le with a BOM. Command strings passed here support things like `\u003e`, `|`, aliases, and posix-like powershell\ncommands.\n\n### HttpClient\n\nThe `httpclient` package wraps `@actions/http-client`.  `HttpClient` provides a lightweight http client, with the\nability to send, `Flow`s and text, and set default and per-request headers. While the typed result methods are provided,\ntyped requests should usually be handled via `JsonHttpClient` in the `serialization` artifact.\n\n## Gradle Plugin\n\nThe gradle plugin (`com.github.rnett.ktjs-github-action`) can Kotlin JS with bundling for GitHub Actions, since the\nKotlin JS plugin doesn't support bundling NodeJS yet.\n\nThere are two functions you can call in your build script:\n\n* `com.rnett.action.githubAction`, called in the `js` target block to configure the target for GitHub actions. It\n  configures a browser target, but with node dependencies in Webpack, and adds a task to generate the custom webpack\n  config. This replaces `browser` or `nodejs`.\n* `com.rnett.action.generateAutoBuildWorkflow`, called anywhere. Generates a GitHub actions workflow for the project to\n  build and commit the distributable on push, in case it wasn't built locally. This keeps it up to date with your latest\n  changes. By default, if called with a `Project` receiver, generates it in `$rootDir/.github/workflows/`\n\n## Examples\n\nThe [test action](./test-action) and its [metadata file](./.github/actions/test-action/action.yml)\n\nhttps://github.com/rnett/find-regex\n\nhttps://github.com/rnett/publish-docs\n\nhttps://github.com/rnett/import-gpg-key\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frnett%2Fkotlin-js-action","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frnett%2Fkotlin-js-action","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frnett%2Fkotlin-js-action/lists"}