Skip to content

A found .ghadocs.json beats every INPUT_* variable #694

Description

@Jamie-BitFlight

What happens

When a .ghadocs.json is found, its values win over the action's INPUT_* environment variables. An action input can never override a value the config file sets.

Where

src/inputs.ts, loadConfig() registers nconf stores in this order: config.argv(...), then config.file(configFilePath), then config.env(...). nconf resolves a key from the first store that has it, so the file beats the environment. The config path comes from path.resolve('.ghadocs.json'), which resolves against process.cwd().

Live consequence in this repo's CI

.github/workflows/integration-test.yml runs against catalystcommunity/action-release-action, which ships a .ghadocs.json whose paths.action is an absolute /home/runner/work/... path. The job works only because it runs from the workspace root, where no .ghadocs.json exists. Run from inside the target checkout, the file is found, its path beats INPUT_ACTION, and generation exits 1 with Failed to load ... action.yaml. Reproduced by cloning the target and running the built CLI from both directories.

Impact

An action user who commits a .ghadocs.json and also sets with: inputs gets the file's values silently. The integration job's coverage of that target depends on its working directory, not on the precedence being right.

Decision needed

Which should win — the file or the action input — and whether docs/tool-contract.md should state the cascade.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions