Skip to content

Cross-Job Output Masking #38345

Description

@jaroslawgajewski

Problem

GHES secret masking blanks all activation job outputs when output values contain substrings matching registered secrets. Downstream jobs (agent, conclusion, detection, safe_outputs) receive empty strings for needs.activation.outputs.* references.

Impact

  • artifact_prefix**: Downstream jobs try to download activation instead of <hash>-activation, failing with "Artifact not found for name: activation".
  • target_repo / target_repo_name**: The Derive GitHub App owner step fails with exit 1 because GH_AW_TARGET_REPOSITORY is empty. Additionally, target_repo is never defined as an activation job output — the compiler emits references to needs.activation.outputs.target_repo in downstream jobs but never adds it to the activation job's outputs: block.

Current Workaround

  • Each downstream job computes its own artifact prefix locally using compute_artifact_prefix.sh (step-level outputs within the same job bypass cross-job masking).
  • Add || github.repository fallback to target_repo and || github.event.repository.name to target_repo_name.

Suggested Fix

  1. Compute artifact_prefix locally in each downstream job instead of passing it via cross-job outputs.
  2. Define target_repo in the activation job's outputs: block, and compute it locally in downstream jobs to be resilient against GHES secret masking.
  3. Add || github.repository / || github.event.repository.name fallbacks to all cross-job target_repo references as a defense-in-depth measure.

Activity

  1. locked and limited conversation to collaborators on Jun 10, 2026
  2. unlocked this conversation on Jun 10, 2026
  3. pelikhan commented on Oct 7, 2026

    @pelikhan
    Collaborator

    Status (2026-10-07): Open; the GHES masking fix is not merged.

    #39742 proposed computing artifact prefixes in each downstream job and adding fallback repository expressions, but that draft PR was closed without merging on June 18. The current compiler does define target_repo and target_repo_name as activation job outputs for non-inlined workflow_call workflows, addressing the missing-output declaration noted here. However, downstream artifact names still use needs.activation.outputs.artifact_prefix, and checkout/GitHub App paths still read needs.activation.outputs.target_repo / target_repo_name without the proposed masking-resistant fallback. Defining those outputs alone does not prevent GHES from blanking them across jobs.

    Remaining work: move prefix calculation into each affected downstream job, make target-repository resolution resilient to masked job outputs, and validate the compiled workflow on GHES. Until then, the locally computed prefix and repository fallbacks described in the issue remain the practical workaround. The broader GHES tracking issue #39889 was closed, but this specific issue remains open.

  4. pelikhan commented on Oct 7, 2026

    @pelikhan
    Collaborator

    @copilot apply fix with local prefix computation.

  5. pelikhan commented on Oct 7, 2026

    @pelikhan
    Collaborator

    Status (2026-10-07; Maintainer direction): The October 7 maintainer discussion says the GHES masking fix is not merged, notes that #39742 closed unmerged, and explicitly requests a fix using local prefix computation. The next step is to compute artifact prefixes in affected downstream jobs, make target-repository resolution resilient to masked outputs, and validate the compiled workflow on GHES.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions