This Action evaluates a checked-in JSON manifest, reports a self-declared subset of AATS v0.9 readiness, fails CI on missing controls, and optionally posts a PR comment. It does not discover runtime assets, certify a system, or assert an independent audit.
Callers can use:
name: AATS readiness
on: [pull_request]
permissions:
contents: read
pull-requests: write # only if comment: true
jobs:
readiness:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: ColomboAI-com/aats-action@v1
with:
manifest: aats.json
comment: 'true'The Action evaluates untrusted manifest data as JSON without shell interpolation. PR comments require pull-requests: write, an accessible event token, and comment: 'true'; fork PRs with read-only tokens still receive job output. Pin a full release SHA when your supply-chain policy requires immutable actions.
PASS means the declared manifest satisfied 11 static checks spanning 11 of the 25 AATS v0.9 domains. The report always states that coverage. It is not an AATS-wide readiness determination, certificate, independent assessment, or proof that runtime controls are effective.