OSS GitHub Actions hygiene leaderboard

Live ranking of 40 popular OSS repositories by their GitHub Actions workflow hygiene. Lower score = better. Powered by ci-doctor (14 rules) and gha-budget (per-job pricing). Workflow YAML re-fetched from each repo every day.

Last updated 2026-07-27 16:16 UTC · raw data (JSON) · scan your own repo · original 20-repo report

New report
State of OSS CI Hygiene 2026 (Edition 1) · the data on this page, packaged as a 12-page PDF + raw JSON snapshot for $14.
Get the report →
Repos ranked
40
Workflows scanned
553
Total findings
2,387
Modeled $/mo combined
$102,359

Cleanest 5 (lowest score)

  1. sveltejs/svelte 1.50
  2. mui/material-ui 1.59
  3. vuejs/core 1.83
  4. TanStack/query 2.00
  5. gatsbyjs/gatsby 2.00

Most findings per workflow (highest score)

  1. remix-run/remix 13.63
  2. rollup/rollup 11.90
  3. axios/axios 9.63
  4. pnpm/pnpm 9.30
  5. parcel-bundler/parcel 8.25

Top rules across all repos

RuleHits
missing-timeout927
deprecated-action283
missing-cache260
missing-concurrency174
pinned-action-sha168

Full ranking (sorted by hygiene score)

# Trend Repo Score WFs Findings E/W/I $/run $/mo*
1 - sveltejs/svelte · scan 1.50 4 7 0/5/2 $0.45 $403
2 - mui/material-ui · scan 1.59 17 30 0/24/6 $0.96 $864
3 - vuejs/core · scan 1.83 9 17 0/16/1 $0.83 $749
4 - TanStack/query · scan 2.00 4 9 0/7/2 $0.38 $346
5 - gatsbyjs/gatsby · scan 2.00 1 2 0/2/0 $0.06 $58
6 - jestjs/jest · scan 2.09 11 23 0/23/0 $1.34 $1,210
7 - storybookjs/storybook · scan 2.34 16 41 0/34/7 $1.66 $1,498
8 - ReactiveX/rxjs · scan 2.50 4 12 0/8/4 $0.38 $346
9 - fastify/fastify · scan 2.65 20 57 0/49/8 $1.41 $1,267
10 - sindresorhus/got · scan 3.00 1 3 0/3/0 $0.00 $0
11 - nodejs/node · scan 3.00 42 120 6/102/12 $6.40 $5,760
12 - lodash/lodash · scan 3.06 8 26 0/23/3 $0.64 $576
13 - swc-project/swc · scan 3.34 16 56 0/51/5 $3.01 $2,707
14 - remix-run/react-router · scan 3.50 13 48 0/43/5 $1.15 $1,037
15 - nestjs/nest · scan 3.50 1 5 0/2/3 $0.06 $58
16 - date-fns/date-fns · scan 3.83 6 23 0/23/0 $0.38 $346
17 - microsoft/TypeScript · scan 3.97 17 73 0/62/11 $1.79 $1,613
18 - chakra-ui/chakra-ui · scan 4.17 3 13 0/12/1 $0.51 $461
19 - microsoft/playwright · scan 4.33 20 90 0/83/7 $4.54 $4,090
20 - nuxt/nuxt · scan 4.43 30 86 26/50/10 $2.50 $2,246
21 - eslint/eslint · scan 4.55 10 48 0/43/5 $1.54 $1,382
22 - tailwindlabs/tailwindcss · scan 4.63 4 23 0/14/9 $1.60 $1,440
23 - vercel/next.js · scan 4.71 36 150 13/124/13 $3.65 $3,283
24 - preactjs/preact · scan 4.81 8 29 6/18/5 $0.70 $634
25 - vitejs/vite · scan 5.12 13 41 13/27/1 $1.15 $1,037
26 - npm/cli · scan 5.23 26 135 3/122/10 $2.56 $2,304
27 - expressjs/express · scan 5.25 4 18 2/14/2 $0.38 $346
28 - prisma/prisma · scan 5.32 17 91 0/90/1 $14.59 $13,133
29 - facebook/react · scan 5.45 22 129 0/111/18 $16.38 $14,746
30 - prettier/prettier · scan 5.59 16 47 22/22/3 $0.96 $864
31 - sequelize/sequelize · scan 6.44 9 41 9/30/2 $5.25 $4,723
32 - biomejs/biome · scan 6.74 25 164 12/113/39 $0.64 $576
33 - electron/electron · scan 6.98 47 202 73/89/40 $3.01 $2,707
34 - webpack/webpack · scan 8.10 10 47 18/25/4 $1.66 $1,498
35 - denoland/deno · scan 8.18 11 99 0/81/18 $21.89 $19,699
36 - parcel-bundler/parcel · scan 8.25 6 52 0/47/5 $0.90 $806
37 - pnpm/pnpm · scan 9.30 25 129 55/61/13 $1.60 $1,440
38 - axios/axios · scan 9.63 8 53 12/41/0 $2.88 $2,592
39 - rollup/rollup · scan 11.90 5 37 13/17/7 $0.70 $634
40 - remix-run/remix · scan 13.63 8 111 0/107/4 $3.20 $2,880
Methodology. Each repo's .github/workflows/*.yml is fetched fresh from the GitHub public API daily. ci-doctor emits findings against 14 rules. Score = (errors×3 + warns×1 + info×0.5) / workflow_count. Cost columns assume 8 min/job, 30 runs/day, GitHub-hosted standard ubuntu-latest pricing. Trend column compares to the previous day's snapshot. Self-hosted and large-runner jobs are not priced.
This is not an attack on any of these projects. They all ship excellent software. The point of a public, ranked, daily-updated leaderboard is that the same patterns show up everywhere, and seeing real numbers is more useful than abstract advice. To request removal from the list, open an issue on depmedicdev-byte/depmedicdev-byte.github.io.