Inputs are wrong in post step when action is called through a nested composite action
@v-Kaniska244 arbeitet bereits daran.
Seit 06.8.2026.
Bewertung
Dieses Issue wurde noch nicht bewertet.
Beschreibung
Description
When devcontainers/ci is called from within a composite action, images are built correctly but pushed under the wrong tags (or not at all). The push happens in the post step at main.ts#L255, which re-reads inputs via core.getInput('imageTag') and core.getInput('imageName'). At post time, those calls return incorrect values.
Root cause
This is a known GHA runner bug: when a node action with a post step is called through a composite action, the runner restores the wrong INPUT_* environment for the post step. Instead of the values the action itself received, it receives the input values of the nearest ancestor composite action.
- actions/runner#3514 - Wrong environment passed to node post when called by composite called by composite action
- actions/runner#2030 - Composite: Nested actions post steps have the wrong context
To reproduce
You can view an MVCE demonstrating this issue at: https://github.com/iaingalloway/devcontainers-ci-inputs-mcve
You can see an affected workflow run:
-
The image is built with the correct tag here: https://github.com/iaingalloway/devcontainers-ci-inputs-mcve/actions/runs/24731494052/job/72346898558#step:6:3
-
And the image is pushed with the wrong tag here: https://github.com/iaingalloway/devcontainers-ci-inputs-mcve/actions/runs/24731494052/job/72346898558#step:6:3
You can view an MCVE of the underlying issue in actions/runner at: https://github.com/iainlane/composite-action-inputs-mvce
Call devcontainers/ci from a composite action that itself receives imageName/imageTag as inputs:
.github/workflows/repro.yml:
name: Post hook sees wrong input
on:
workflow_dispatch:
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- name: Log in to registry
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Call outer composite
uses: ./.github/actions/outer-composite
.github/actions/outer-composite/action.yml:
# Outer composite action
name: Outer composite
description: Sets the value to bar and calls the inner composite
runs:
using: composite
steps:
- name: Call inner composite
uses: ./.github/actions/inner-composite
with:
image-tag: foo
.github/actions/inner-composite/action.yml:
name: Inner composite
description: Passes a value to the devcontainers/ci action
inputs:
image-tag:
description: Image tag to build and push
required: true
runs:
using: composite
steps:
- name: Build and push devcontainer image
uses: devcontainers/ci@b63b30de439b47a52267f241112c5b453b673db5
with:
imageName: ghcr.io/${{ github.repository }}/devcontainer
imageTag: ${{ inputs.image-tag }}
push: always
subFolder: src
./src/devcontainer.json:
{
"image": "mcr.microsoft.com/devcontainers/base@sha256:e389149057371298eaeb72e736fc2c4dcb79974de222dd471d2e6d675d2f61c4"
}
Observed: post step attempts to push latest (by default, because INPUT_IMAGETAG is not set in the post context).
Expected: post step should push foo.
Workaround (for maintainers)
The fix used by github/codeql-action (codeql-action#2557) is to persist inputs in main using saveState, then read them back from STATE_* in the post step:
In main:
core.saveState('imageName', imageName);
core.saveState('imageTag', imageTag);
core.saveState('push', push);
core.saveState('platform', platform);
In post, replace core.getInput('imageName') / core.getInput('imageTag') / core.getInput('push') / core.getInput('platform') with:
core.getState('push')
core.getState('imageName')
core.getState('imageTag')
core.getState('platform')
This sidesteps the runner bug entirely since state is stored in STATE_* env vars which are not subject to the same mis-evaluation.
Happy to submit a PR with this change if it would be helpful!
- Vorherrschende Sprache
- TypeScript
- Sterne
- 496
- Forks
- 102
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus devcontainers/ci
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 68/100
devcontainers/ci#446 ·
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
devcontainers/ci#445 ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 45/100
devcontainers/ci#444 · 1 Kommentar · 3 Reaktionen ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 45/100
devcontainers/ci#437 ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 35/100
devcontainers/ci#430 ·
Alle Issues in devcontainers/ci
Ähnliche Issues
-
triage
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
mermaid-js/mermaid-live-editor#2053 ·
Maintainer antworten meist innerhalb von 1 Tag
-
factory
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
jessepollak/home#1455 ·
Maintainer antworten meist innerhalb von 1 Tag
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 95/100
lingdojo/kana-dojo#31227 · 1 Kommentar · 5 Reaktionen ·
Maintainer antworten meist innerhalb von 1 Tag
-
mobile: device viewer shows dark status bar icons on its dark backdrop in light mode (Android)Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 92/100
appandflow/stim#1838 ·
Maintainer antworten meist innerhalb von 1 Tag