What happens
When a .ghadocs.json is found, its values win over the action's INPUT_* environment variables. An action input can never override a value the config file sets.
Where
src/inputs.ts, loadConfig() registers nconf stores in this order: config.argv(...), then config.file(configFilePath), then config.env(...). nconf resolves a key from the first store that has it, so the file beats the environment. The config path comes from path.resolve('.ghadocs.json'), which resolves against process.cwd().
Live consequence in this repo's CI
.github/workflows/integration-test.yml runs against catalystcommunity/action-release-action, which ships a .ghadocs.json whose paths.action is an absolute /home/runner/work/... path. The job works only because it runs from the workspace root, where no .ghadocs.json exists. Run from inside the target checkout, the file is found, its path beats INPUT_ACTION, and generation exits 1 with Failed to load ... action.yaml. Reproduced by cloning the target and running the built CLI from both directories.
Impact
An action user who commits a .ghadocs.json and also sets with: inputs gets the file's values silently. The integration job's coverage of that target depends on its working directory, not on the precedence being right.
Decision needed
Which should win — the file or the action input — and whether docs/tool-contract.md should state the cascade.
What happens
When a
.ghadocs.jsonis found, its values win over the action'sINPUT_*environment variables. An action input can never override a value the config file sets.Where
src/inputs.ts,loadConfig()registers nconf stores in this order:config.argv(...), thenconfig.file(configFilePath), thenconfig.env(...). nconf resolves a key from the first store that has it, so the file beats the environment. The config path comes frompath.resolve('.ghadocs.json'), which resolves againstprocess.cwd().Live consequence in this repo's CI
.github/workflows/integration-test.ymlruns againstcatalystcommunity/action-release-action, which ships a.ghadocs.jsonwhosepaths.actionis an absolute/home/runner/work/...path. The job works only because it runs from the workspace root, where no.ghadocs.jsonexists. Run from inside the target checkout, the file is found, its path beatsINPUT_ACTION, and generation exits 1 withFailed to load ... action.yaml. Reproduced by cloning the target and running the built CLI from both directories.Impact
An action user who commits a
.ghadocs.jsonand also setswith:inputs gets the file's values silently. The integration job's coverage of that target depends on its working directory, not on the precedence being right.Decision needed
Which should win — the file or the action input — and whether
docs/tool-contract.mdshould state the cascade.