Skip to content

A Local ./ Reference in a Called Reusable Workflow Does Not Run at the Workflow Commit #1886

Description

@ptr727

Finding

scripts/README.md (the sha-pin check description) says local (./) and self-repository ($/) references "run at the workflow commit". For $/ that holds. For a local ./ action reference inside a reusable workflow called from another repository it does not: GitHub resolves a ./ path in the runner workspace, which holds the calling repository's checkout rather than the reusable workflow's commit. That difference is why the hub's tasks use $/ for their own actions (docs/reusable-workflows.md, the hub reusable workflow item).

WORKFLOW.md's test-methodology trace paragraph makes a similar claim ("A local (./) or self-repository ($/) call carries no pin of its own and runs at the workflow commit") and should be checked for the same gap.

Suggested fix

Distinguish the two: a $/ reference resolves at the containing workflow file's commit, while a ./ reference resolves against whatever the job checked out.

Found by a local strict review on #1885, outside that pull request's diff.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions