Skip to content

update-pull-request target from a safe-outputs.needs job output is blanked in the agent config and rejected on workflow_dispatch #64021

Description

@tsm-harmoney

Summary

When update-pull-request.target is set to the output of a job listed in safe-outputs.needs, the compiler
replaces it with "" in the agent job's safe-outputs config. The MCP server treats "" as triggering and
rejects every update_pull_request call on workflow_dispatch, although the handler job's config still has
the correct PR number.

Reproduction

on:
  workflow_dispatch:

jobs:
  setup:
    runs-on: ubuntu-latest
    outputs:
      pull_request_number: ${{ steps.create-pr.outputs.pull_request_number }}
    steps:
      - id: create-pr
        run: echo "pull_request_number=123" >> "$GITHUB_OUTPUT"

# the agent job depends on setup, so needs.setup resolves there
steps:
  - run: echo "PR #${{ needs.setup.outputs.pull_request_number }}"

safe-outputs:
  needs: [setup]
  update-pull-request:
    target: ${{ needs.setup.outputs.pull_request_number }}

After gh aw compile:

Config update_pull_request.target
Agent job (GH_AW_SAFE_OUTPUTS_CONFIG) ""
safe_outputs job (GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG) ${{ needs.setup.outputs.pull_request_number }}

The agent's update_pull_request call is then rejected with:

update_pull_request requires a pull request context but the workflow is running on a "workflow_dispatch" event. [...] the workflow must configure update-pull-request: target: '*' and you must supply pull_request_number.

Expected

The PR number is accepted as a fixed target, as
documented
("triggering" (default), "*", or number).

Root cause

Line references are for v0.89.21.

  1. sanitizeAgentSafeOutputsConfig (pkg/workflow/compiler_safe_outputs_builder.go:181, added in Fix actionlint error: agent job referencing needs.approval_allowlist it never depends on #54028)
    blanks needs.<job> expressions for every job in safe-outputs.needs, assuming the agent job never
    depends on those jobs. Here the agent job does depend on setup, so the expression would resolve fine.
  2. actions/setup/js/safe_outputs_handlers.cjs:2990 falls back to "triggering" for an empty target
    (updatePRConfig.target || "triggering"), so the blanked fixed target becomes a triggering target.

Suggested fix

  • Only blank needs.<job> references for jobs the agent job does not depend on, and/or
  • don't treat a blanked target as triggering in the MCP server; leave the check to the handler.

Versions

  • Works: v0.85.4
  • Broken: v0.87.2 and later, including v0.89.22 and main

Thanks for all your work on gh-aw!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions