OSS GitHub Actions hygiene leaderboard

Live ranking of 40 popular OSS repositories by their GitHub Actions workflow hygiene. Lower score = better. Powered by ci-doctor (14 rules) and gha-budget (per-job pricing). Workflow YAML re-fetched from each repo every day.

Last updated 2026-09-11 17:31 UTC · raw data (JSON) · scan your own repo · original 20-repo report

New report
State of OSS CI Hygiene 2026 (Edition 1) · the data on this page, packaged as a 12-page PDF + raw JSON snapshot for $14.
Get the report →
Repos ranked
40
Workflows scanned
572
Total findings
2,896
Modeled $/mo combined
$98,898

Cleanest 5 (lowest score)

  1. sveltejs/svelte 1.50
  2. TanStack/query 2.00
  3. gatsbyjs/gatsby 2.00
  4. storybookjs/storybook 2.24
  5. fastify/fastify 2.65

Most findings per workflow (highest score)

  1. remix-run/remix 24.57
  2. axios/axios 17.50
  3. biomejs/biome 15.60
  4. remix-run/react-router 14.63
  5. rollup/rollup 11.90

Top rules across all repos

RuleHits
missing-timeout1008
deprecated-action689
missing-cache284
artifact-no-retention171
missing-concurrency169

Full ranking (sorted by hygiene score)

# Trend Repo Score WFs Findings E/W/I $/run $/mo*
1 - sveltejs/svelte · scan 1.50 4 7 0/5/2 $0.45 $403
2 - TanStack/query · scan 2.00 4 9 0/7/2 $0.38 $346
3 - gatsbyjs/gatsby · scan 2.00 1 2 0/2/0 $0.06 $58
4 - storybookjs/storybook · scan 2.24 19 46 0/39/7 $1.86 $1,670
5 - fastify/fastify · scan 2.65 20 57 0/49/8 $1.41 $1,267
6 - sindresorhus/got · scan 3.00 1 3 0/3/0 $0.00 $0
7 - lodash/lodash · scan 3.06 8 26 0/23/3 $0.64 $576
8 - mui/material-ui · scan 3.21 17 40 9/24/7 $0.96 $864
9 ↑1 swc-project/swc · scan 3.47 16 58 0/53/5 $2.82 $2,534
10 ↑1 nestjs/nest · scan 3.50 1 5 0/2/3 $0.06 $58
11 ↑1 date-fns/date-fns · scan 3.83 6 23 0/23/0 $0.38 $346
12 ↑1 chakra-ui/chakra-ui · scan 4.17 3 13 0/12/1 $0.51 $461
13 ↑1 vercel/next.js · scan 4.57 29 117 11/93/13 $3.14 $2,822
14 ↑1 tailwindlabs/tailwindcss · scan 4.63 4 23 0/14/9 $1.60 $1,440
15 ↑1 preactjs/preact · scan 4.69 8 28 6/17/5 $0.70 $634
16 ↑1 nuxt/nuxt · scan 4.71 26 78 24/47/7 $2.62 $2,362
17 ↑1 vitejs/vite · scan 4.81 13 44 10/31/3 $1.22 $1,094
18 ↑1 vuejs/core · scan 4.83 9 26 9/16/1 $0.83 $749
19 ↑1 npm/cli · scan 5.00 26 133 1/122/10 $2.56 $2,304
20 ↑1 eslint/eslint · scan 5.05 10 53 0/48/5 $1.73 $1,555
21 ↑1 facebook/react · scan 5.12 26 143 0/123/20 $16.83 $15,149
22 ↑1 prettier/prettier · scan 5.59 16 47 22/22/3 $0.96 $864
23 ↑1 nodejs/node · scan 5.98 45 171 52/107/12 $6.66 $5,990
24 ↑1 prisma/prisma · scan 6.09 17 61 23/31/7 $2.37 $2,131
25 ↑1 jestjs/jest · scan 6.18 11 40 14/26/0 $1.47 $1,325
26 ↑1 ReactiveX/rxjs · scan 6.27 11 41 15/22/4 $2.50 $2,246
27 ↑1 sequelize/sequelize · scan 6.44 9 41 9/30/2 $5.06 $4,550
28 ↑1 electron/electron · scan 6.57 53 220 75/101/44 $3.33 $2,995
29 ↑1 webpack/webpack · scan 7.83 12 52 22/26/4 $1.92 $1,728
30 ↑1 denoland/deno · scan 8.05 11 97 0/80/17 $21.89 $19,699
31 ↑1 parcel-bundler/parcel · scan 8.25 6 52 0/47/5 $0.90 $806
32 ↑1 microsoft/playwright · scan 9.45 21 121 40/76/5 $5.31 $4,781
33 ↑1 expressjs/express · scan 10.50 4 25 9/14/2 $0.38 $346
34 ↑1 pnpm/pnpm · scan 11.22 25 155 67/71/17 $1.60 $1,440
35 ↑1 microsoft/TypeScript · scan 11.75 10 77 23/43/11 $1.28 $1,152
36 ↑1 rollup/rollup · scan 11.90 5 37 13/17/7 $0.70 $634
37 ↓28 remix-run/react-router · scan 14.63 19 175 61/76/38 $3.65 $3,283
38 - biomejs/biome · scan 15.60 24 235 80/114/41 $0.58 $518
39 - axios/axios · scan 17.50 8 74 33/41/0 $2.88 $2,592
40 - remix-run/remix · scan 24.57 14 241 61/142/38 $5.70 $5,126
Methodology. Each repo's .github/workflows/*.yml is fetched fresh from the GitHub public API daily. ci-doctor emits findings against 14 rules. Score = (errors×3 + warns×1 + info×0.5) / workflow_count. Cost columns assume 8 min/job, 30 runs/day, GitHub-hosted standard ubuntu-latest pricing. Trend column compares to the previous day's snapshot. Self-hosted and large-runner jobs are not priced.
This is not an attack on any of these projects. They all ship excellent software. The point of a public, ranked, daily-updated leaderboard is that the same patterns show up everywhere, and seeing real numbers is more useful than abstract advice. To request removal from the list, open an issue on depmedicdev-byte/depmedicdev-byte.github.io.