Skip to content
Back to skills

Shared Workflow Org Refs

ASecurity

Use when creating or editing GitHub Actions workflows that call reusable workflows (uses: OWNER/repo/.github/workflows/...) — org owner references must be the literal current org, and shared-CI homes are under dryvist.

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 19, 2026
ai-agentsexpressgitapi

Works with

  • api

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add dryvist/claude-code-plugins --skill shared-workflow-org-refs --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Shared Workflow Org Refs?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Shared Workflow Org Refs
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dryvist-shared-workflow-org-refs/badge)](https://www.skillsdirectory.com/skills/dryvist-shared-workflow-org-refs)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: shared-workflow-org-refs
description: "Use when creating or editing GitHub Actions workflows that call reusable workflows (uses: OWNER/repo/.github/workflows/...) — org owner references must be the literal current org, and shared-CI homes are under dryvist."
---

# Shared Workflow Org References

GitHub Actions reusable-workflow and action `uses:` clauses are the one place the
"don't rewrite `JacobPEvans/*` on sight — the redirect holds" rule does NOT apply.

Two hard GitHub constraints:

- `uses:` cannot contain expressions or variables — the owner is always a literal.
  `uses: ${{ vars.X }}/repo/...@ref` is rejected. No org variable can centralize it.
- `uses:` does NOT follow repository transfer/rename redirects (by design). API, git, and the browser DO follow them; Actions does not.

Consequence: when a shared-CI repo changes orgs, every consumer's `uses:` fails at parse time
(the run shows zero jobs and "workflow was not found"). There is no runtime variable that prevents this.

## Canonical home: dryvist

**dryvist is the canonical home for everything dryvist uses.** Anything a dryvist
repo consumes — reusable workflows, presets, policies — belongs under `dryvist/*`.
`JacobPEvans-personal/*` may depend on `dryvist/*`; `dryvist/*` must **never** depend
on `JacobPEvans-personal/*`. When a shared workflow is used by dryvist, its home is
`dryvist/.github` (or the relevant `dryvist/*` repo), not the personal account.

Because `uses:` does not follow redirects, reference each workflow by its literal
**current** owner from the table below until a pending relocation actually lands.

| Shared-CI workflow set | Current home | Status |
| --- | --- | --- |
| `ai-workflows` reusable workflows | `dryvist/ai-workflows` | canonical |
| Nix reusable workflows (`_nix-validate.yml`, `_nix-build.yml`) | `dryvist/.github` | canonical |
| Release-please (`_release-please.yml`) | `dryvist/.github` | canonical — org-native (dryvist release App, major-bump block, auto-merge) |
| `_markdown-lint`, `_file-size`, `_osv-scan`, `_ci-gate`, … | `JacobPEvans-personal/.github` | **pending relocation to `dryvist/.github`** |

Nix and release-please were deliberately relocated to `dryvist/.github` (the org owns
its own CI). The remaining non-Nix `.github` workflows are still in
`JacobPEvans-personal/.github` **only until they are moved the same way** — that is a
transitional home, not a permanent one. Repoint consumers via the sweep below as each
moves; do not move any back to the personal account.

## Rules

- In `uses:`, always reference the literal current owner above.
- Do NOT replace a reusable-workflow call with a `gh workflow run` / checkout `vars.*` dispatcher
  just to gain a variable: that loses required-check status, inputs/outputs, and `secrets: inherit`.

## If a shared-CI repo must move anyway (sweep)

1. `gh search code 'OLD_OWNER/REPO' --owner dryvist` (and `--owner JacobPEvans-personal`), filtered to `.github/workflows/*.yml`.
2. Per consumer repo: swap only the `uses:` owner segment, preserving path and `@ref`; one PR per repo.
3. Skip docs and files that are not reusable-workflow callers.
4. Token tiers: dryvist repos → DRYVIST; JacobPEvans-personal repos → PRIVATE.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…