Repository navigation
Cross-Job Output Masking #38345
Description
Activity
- locked and limited conversation to collaborators
on Jun 10, 2026 - unlocked this conversation
on Jun 10, 2026 Status (2026-10-07): Open; the GHES masking fix is not merged.
#39742 proposed computing artifact prefixes in each downstream job and adding fallback repository expressions, but that draft PR was closed without merging on June 18. The current compiler does define
target_repoandtarget_repo_nameas activation job outputs for non-inlinedworkflow_callworkflows, addressing the missing-output declaration noted here. However, downstream artifact names still useneeds.activation.outputs.artifact_prefix, and checkout/GitHub App paths still readneeds.activation.outputs.target_repo/target_repo_namewithout the proposed masking-resistant fallback. Defining those outputs alone does not prevent GHES from blanking them across jobs.Remaining work: move prefix calculation into each affected downstream job, make target-repository resolution resilient to masked job outputs, and validate the compiled workflow on GHES. Until then, the locally computed prefix and repository fallbacks described in the issue remain the practical workaround. The broader GHES tracking issue #39889 was closed, but this specific issue remains open.
@copilot apply fix with local prefix computation.
- linked a pull request that will close this issueAvoid GHES masking of cross-job workflow outputs #66678
on Oct 7, 2026 Status (2026-10-07; Maintainer direction): The October 7 maintainer discussion says the GHES masking fix is not merged, notes that #39742 closed unmerged, and explicitly requests a fix using local prefix computation. The next step is to compute artifact prefixes in affected downstream jobs, make target-repository resolution resilient to masked outputs, and validate the compiled workflow on GHES.
Problem
GHES secret masking blanks all activation job outputs when output values contain substrings matching registered secrets. Downstream jobs (agent, conclusion, detection, safe_outputs) receive empty strings for
needs.activation.outputs.*references.Impact
artifact_prefix**: Downstream jobs try to downloadactivationinstead of<hash>-activation, failing with "Artifact not found for name: activation".target_repo/target_repo_name**: TheDerive GitHub App ownerstep fails with exit 1 becauseGH_AW_TARGET_REPOSITORYis empty. Additionally,target_repois never defined as an activation job output — the compiler emits references toneeds.activation.outputs.target_repoin downstream jobs but never adds it to the activation job'soutputs:block.Current Workaround
compute_artifact_prefix.sh(step-level outputs within the same job bypass cross-job masking).|| github.repositoryfallback totarget_repoand|| github.event.repository.nametotarget_repo_name.Suggested Fix
artifact_prefixlocally in each downstream job instead of passing it via cross-job outputs.target_repoin the activation job'soutputs:block, and compute it locally in downstream jobs to be resilient against GHES secret masking.|| github.repository/|| github.event.repository.namefallbacks to all cross-jobtarget_reporeferences as a defense-in-depth measure.