Marketplace Publishing

Publishing an Action to the Marketplace

count-books lives inside BookNest, so only BookNest can use it by path. Sharing it means moving it into its own public repository, publishing a release, and accepting the GitHub Marketplace 29 Developer Agreement in the web interface, so this step is not run here. GitHub 29 requires one action.yml at the repository root, a name that is not already an action, a GitHub account you don't own or a Marketplace category, and two-factor authentication. The banner on the metadata file offers Draft a release, where you tick Publish this Action to the GitHub Marketplace, choose categories and create a tag such as v1.0.0; users then write uses: owner/repo@v1, a major tag you move to each compatible release.

Whoever controls a repository can move its tags, which is how the compromised tj-actions/changed-files action reached thousands of workflows at once in March 2025. Pin third-party actions to a full commit SHA (uses: owner/repo@<40-hex-sha> # v1.2.0) and let Dependabot 29 propose updates.