scieee AI-readable full text Open interactive document viewer

Automation and Reuse Practices in GitHub Actions Workflows: A Practitioner's Perspective

Onsori Delicheh, Hassan; CARDOEN, Guillaume; Decan, Alexandre; Mens, Tom

Abstract

This is the dataset of the paper "Automation and Reuse Practices in GitHub Actions Workflows: A Practitioner’s Perspective" by Hassan Onsori Delicheh, Guillaume Cardoen, Alexandre Decan and Tom Mens (Software Engineering Lab, University of Mons, Belgium). This paper presents a survey amongst GitHub Actions practitionners to understands the automation and reuse practices used in GitHub Actions workflows. survey.tar.gz contains the HTML version of the questions asked to every participants, whereas survey.pdf represents the same survey in a PDF format. data.csv represents the anonymized version of the answers by the participants. A replication package analysing this dataset can be found on Zenodo.

Full text

Study on GitHub Actions workflow This survey explores the practices of maintaining GitHub Actions workflows. By understanding these practices, we aim to seek opportunities for providing better automated support for workflow maintenance. The survey is structured into four topics. It should take no more than 15 minutes to complete it. Thanks in advance for completing this questionnaire. There are 18 questions in this survey. Rate your familiarity in using some CI/CD service in any of the software repositories that you are (or have been) involved in. Please note that if you are 'Not familiar at all' with GitHub Actions, the survey will conclude, and you will be directed to the last page. * Please choose the appropriate response for each item: Not familiar at all Slightly familiar Moderately familiar Very familiar GitHub Actions Other CI/CD services (e.g., GitLab CI/CD, Travis, Jenkins, Azure DevOps, Circle CI, ...) How important do you consider the following characteristics when maintaining workflows? • Reliability: My workflowshould operatefailure-free for a specified period of time in a specified environment. • Performance: My worklowshouldperform its functions within a specified time and with efficient use of resources. • Understandability: My workflow should be easy to read and understand. • Testability: My workflowshould be easy to test and debug. • Modifiability: My workflowshould be easy to change or adapt. • Reusability: My workflowor specific parts of it should be easily reusable in other contexts. • Security: My workflowshould not have security weaknesses andvulnerabilitiesthat could be (ab)used by an attacker. * Please choose the appropriate response for each item: I don’t know Unimportant Slightly important Moderately Important Very important Reliability Performance Understandability Testability Modifiability Reusability I don’t know Unimportant Slightly important Moderately Important Very important Security How frequently do you use the GitHub Actions workflows to automate the following tasks? • Building: Automate the compilation and building of artefacts. • Testing: Automate the testing of artefacts. • Deployment: Automatically deploy applications to various environments (e.g., AWS, Azure, Google Cloud, ...). • Code Quality Analysis: Analyse the code (statically or dynamically) for quality, compliance of coding standards, linting, code smells, and so on. • Version and Release Management: Create and publish new versions and releases, generaterelease notes and changelogs, ... • Infrastructure and Configuration Management: Manage configurations and (cloud) infrastructures (e.g., Terraform, CloudFormation, ...). • Security Analysis:Secret management, code signing, detecting vulnerabilities and weaknessesin workflows, and so on. • Documentation: Build and deploy documentation(e.g., developer or end-user documentation, websites). • Internal Reporting: Generate internal reports or badges related to coverage results, test results, and so on. • Issue Management: Automate issue-related tasks such as triaging, labeling, assigning, closing issues, and discussing issues. • Pull Request Management: Automate pull request related tasks like merging, reviewing, triaging, assigning, and closingthem. • Dependency Management: Automatedependency updates, scanvulnerabilities in dependencies, ... • Compliance Checking: Check for compliance to licences and policies. • External Communication: Automate with external communication channels such as email, Slack, ... • Health and Performance Monitoring: Analyse system or network performance and related health metrics. * Please choose the appropriate response for each item: I don’t know Never SometimesFrequently (Nearly) always Building Testing Deployment Code Quality Analysis Version and Release Management Infrastructure and Configuration Management Security Analysis Documentation Internal Reporting Issue Management I don’t know Never SometimesFrequently (Nearly) always Pull Request Management Dependency Management Compliance Checking External Communication Health and Performance Monitoring Other: Please describe below. Please briefly describe. * Please write your answer here: How frequently do you use the following mechanisms to create new workflows? * Please choose the appropriate response for each item: I don't know Never SometimesFrequently (Nearly) always I write my workflows from scratch I rely on a starter workflow template suggested through the GitHub UI I rely on a workflow template provided elsewhere I base myself on one of my own workflows I base myself on someone else's workflow I am assisted by a tool (e.g., copilot) I make use of another source (forum, Q&A platform, ...) Other: Please describe below Please describe the other mechanism(s) you use to create new workflows. * Please write your answer here: How frequently do you use the following reuse mechanisms in your workflows? * Please choose the appropriate response for each item: I am unaware of this mechanism Never SometimesFrequently (Nearly) always I use an Action I created myself I use an Action developed by someone else I use a reusable workflow I created myself I use a reusable workflow developed by someone else I copy parts of workflows from my own repository I copy parts of workflows from someone else's repository I copy parts of workflows from another source (forum, Q&A platform, ...) Other: Please describe below. How important do you consider the following characteristics when using an Action in your workflow? • Responsiveness: The extent to which the Action’s maintainers actively react to user requests or engage in discussions. • Popularity: Indicators that signal that there is a community interested in the Action (e.g., as reflected by a high number of stars, watchers, or forks). • Maintenance: Evidence that the Action is modified to correct faults, improve performance or other attributes, or adapt to a changed environment. • Reliability: The failure-free operation of the Action for a specified period of time in a specified environment. • Documentation: The clarity and consistency of the Action's documentation, such as installation and usage instructions. • License compatibility: The compatibility of the Action's license with the intended use of the Action. • Security: The Actionshould not have security weaknesses andvulnerabilitiesthat could be (ab)used by an attacker. • Performance: The ability of the Action to performits functions within a specified time and with efficient use of resources. • Quality: The overall quality of the Actions code base (such as its understandability, simplicity, modularity) and the availability of tests. * Please choose the appropriate response for each item: I don’t UnimportantSlightly Moderately Very know important Important important Responsiveness Popularity Maintenance Reliability Documentation License compatibility Security Performance Quality Other: Please describe below. Please briefly describe. * Please write your answer here: Thank you for participating in this survey. If you would like to leave any remarks concerning this survey or your responses, please fill in the optional field below: Please write your answer here: If you grant us permission to provide you the outcome of this survey or optionally contact you for a follow-up, please leave your email address below: Select all that apply Please choose all that apply: I would like to receive the results of the survey when they are available I agree to be contacted for possible follow-up questions, without any obligation to do so Please leave your email address below: Please write your answer here: Thank you for your time for completing our survey. Your experience matters to us a lot as it will help us understand the practices of maintaining GitHub Actions workflows. Hassan, Guillaume, Alexandre and Tom Software Engineering Lab University of Mons, Belgium [email protected] Submit your survey. Thank you for completing this survey.