Skip to content
Latchkey LogoLatchkey home
Latchkey Learn

GitHub Actions workflow errors

The errors GitHub Actions itself raises: expressions, reusable workflows, permissions and secrets, caching and artifacts, runner labels.

Workflow and YAML syntax

Expressions, contexts, triggers, reusable workflows.

"paths-filter outputs always false"Fix dorny/paths-filter outputs always false in GitHub Actions: the diff base it could not resolve, and the always() skipped on cancelGitHub Actions always() skipped when canceled comes down to when the condition is read. No INPUT_ variables hereGitHub Actions composite action inputs not passed is usually the environment variable habit. github.action_pathA GitHub Actions composite action no such file error means a run step resolved the path against the caller "Unexpected input(s)"GitHub Actions composite action unexpected input is a name comparison against action.yml. Composite steps start at the workspaceA GitHub Actions composite action working-directory is joined onto the workspace, and job defaults never group is requiredGitHub Actions concurrency cancel-in-progress cannot stand alone, because the schema marks group required. Pending, not deadlockedA GitHub Actions concurrency job stuck pending is waiting on a group somewhere else in the repository. Green run, failing legGitHub Actions continue-on-error on a matrix applies to every leg, so one experimental combination turns the "You are not currently on a branch"GitHub Actions detached HEAD after actions/checkout is documented behavior, not a bug. Substituted, then parsedA GitHub Actions env var with special characters breaks a run step because expressions are pasted into the Empty value, no errorA GitHub Actions environment variable not expanding in steps has three separate causes, each with its own 21000 characters, per expressionGitHub Actions exceeded max expression length caps one expression at 21000 characters, not your file. fromJSON matrix failsA GitHub Actions fromJSON matrix fails when the upstream output is empty or is not an array. Two implementations, two textsGitHub Actions fromJSON unable to parse is not the wording the runner uses. A condition that is always trueA GitHub Actions if condition always runs when the value is a string holding an expression. if: always() on cancelGitHub Actions if: always() returns true in every state, cancellation included. YAML rejects it firstA GitHub Actions invalid pattern paths filter is usually rejected by YAML before any filter sees it. "Invalid workflow file"GitHub Actions invalid workflow file on this ref blocks a required check with nothing red. "Invalid workflow reference"GitHub Actions invalid workflow reference means the called workflow is not written in one of three accepted "Job has been skipped"A GitHub Actions job has been skipped (needs) because a job it depends on did not succeed. Three ways to apply nothingWhen GitHub Actions labeler applies no labels the step is usually red, not green. A partial match is enoughGitHub Actions matrix exclude not working usually means it worked too well. Empty is loud, not quietA GitHub Actions matrix from a JSON file rarely fails quietly. One more job than expectedA GitHub Actions matrix include extra job is the rule working, not a bug. "Matrix must define ..."GitHub Actions Matrix must define at least one vector is one of five messages the matrix converter can raise. Created, not rejectedGitHub Actions missing environment production is not what a typo produces. Folded joins your linesA GitHub Actions multiline run script fails when the folded block scalar joins your commands. needs.<job>.outputs emptyGitHub Actions needs outputs empty is almost always an unmapped step output. Not required, still fatalA GitHub Actions on section missing from a file is fatal even though the published schema does not mark it One filter per eventUsing GitHub Actions paths and paths-ignore together is documented as unsupported, and nothing rejects it. pipefail and the shellGitHub Actions pipefail is only applied when a step says shell: bash. "exit code 1"GitHub Actions Process completed with exit code 1 reports the script status, not the reason. Thrown before anything runsGitHub Actions pwsh command not found comes from the runner looking for the shell, not from a script failing. "Required property is missing: jobs"Required property is missing: jobs means the workflow root has no jobs key. env stops at the callGitHub Actions reusable workflow env not inherited is by design, and the calling job cannot declare env at "Invalid input ... referenced workflow"Fix a GitHub Actions reusable workflow input type mismatch: the three declared types, the contexts a with Outputs empty in the callerGitHub Actions reusable workflow outputs empty in the caller means the value was dropped at one of four hops. "workflow was not found"GitHub Actions reusable workflow was not found means the reference resolved to nothing. run-name has three contextsGitHub Actions run-name env not available is a rejected workflow, not a blank title. "This check was skipped"A GitHub Actions skipped job required check reports Success and cannot block a merge. Thirty operations, then stopWhen the GitHub Actions stale action processes nothing, the usual cause is a documented limit or a value that The message moved onA GitHub Actions step cannot have both uses and run, but the published parser no longer says so. The viewer, not the logGitHub Actions step debug logs truncated is about the web viewer rather than the stored log. "steps.<id>.outputs is empty"A GitHub Actions step output empty in an expression is a missing id, a misspelled one, a read that runs too "terminal prompts disabled"GitHub Actions submodule checkout failed almost always means the token cannot read the submodule repository. Neither is trueGitHub Actions success() and failure() both false is what a four-valued status does to a two-valued test. Boolean keys and string valuesGitHub Actions unable to interpret as boolean appears in no parser GitHub ships. "Unable to resolve action"GitHub Actions Unable to resolve action arrives in two forms, and each tells you how far the lookup got "Unexpected symbol"Fix GitHub Actions unexpected symbol in a ${{ }} expression: what the parser rejects, where the position "Unexpected value"GitHub Actions Unexpected Value names a key or a value the workflow schema did not expect. "Unexpected value 'runs-on'"github actions unexpected value runs-on usually means the job is a reusable-workflow caller, not that the key "Unexpected value 'steps'"github actions unexpected value steps is reported with a column. Checked twice, at two momentsGitHub Actions Unexpected value true workflow_call is checked in two passes. "Unrecognized named-value"Fix GitHub Actions unrecognized named-value: env with the one table that says which contexts each workflow "Unrecognized named-value: inputs"Fix GitHub Actions unrecognized named-value: inputs, the error that means no trigger in this file ever "Unrecognized named-value: 'matrix'"GitHub Actions Unrecognized named-value: matrix means the key you used is not on the matrix context list. "Unrecognized named-value: 'secrets'"GitHub Actions unrecognized named-value: secrets means the context is not offered for that key. Three messages, one memoryGitHub Actions workflow not found at ref is a remembered phrase rather than a quotable message. Nothing in the Actions tabA GitHub Actions workflow not triggering is three different states, and only one of them makes a run. "not found on the default branch"GitHub Actions workflow_dispatch not on default branch is why the Run workflow button is missing. "working directory" start failureWhen a GitHub Actions working-directory does not exist the step fails before your command runs. Rejected, not ignoredGitHub Actions working-directory on a uses step does not run the action in the wrong folder. Anchors yes, merge keys noGitHub Actions YAML anchors are documented for GitHub.com, and have been since September 2025. "Invalid input, secrets"Invalid input, secrets is not defined in the referenced workflow means a secrets key landed inside with. "without workflows permission"Refusing to allow a GitHub App to update a workflow is a push rejection, not a workflow error. "Unexpected input(s), valid inputs are"A GitHub Actions unexpected input valid inputs are warning means the runner ignored one of your with keys. The ref is the subjectWorkflow does not have a workflow_dispatch trigger is about the ref you picked, not the default branch.

Caching and artifacts

actions/cache, upload and download artifact, Pages.

cache-hit is emptyA GitHub Actions cache-hit output empty value is what a full miss produces. "node version file... does not exist"When setup-node node version file does not exist, the path was joined to the workspace root. "artifact name already exists"In GitHub Actions, an artifact with this name already exists is a 409 by design: names are unique per run "not saving cache"Cache hit occurred on the primary key explains a cache that never updates: a static key restores forever and "Unable to find any artifacts"In GitHub Actions, download-artifact unable to find any artifacts is a version 3 message. "Artifact has expired"A GitHub Actions artifact has expired failure is a 410 from the download endpoint, not a missing row. "Artifact not found for name"A GitHub Actions Artifact not found for name error is a lookup that came back empty. Artifact upload failedA GitHub Actions artifact upload failed after the glob succeeded points at one of three API calls. "Dependencies lock file is not found"GitHub Actions Dependencies lock file is not found means setup-node read the repository root and gave up. "Get Pages site failed"A GitHub Actions Get Pages site failed error is a 404 from the Pages API, not a permissions problem. "Path Validation Error"A GitHub Actions Path Validation Error caching line is written at info level, so the job stays green and no "reserveCache failed"A GitHub Actions reserveCache failed line is assembled at runtime and belongs to the retired v1 cache Artifact from another runA download-artifact from another workflow run needs github-token, not run-id. "No artifacts named github-pages"No artifacts named github-pages were found means deploy-pages searched this run only. "No Docker tag has been generated"No Docker tag has been generated means every tag rule declined this event, not that the images input is "No files were found"In GitHub Actions, no files were found with the provided path means the upload glob expanded to nothing. Artifact path structureThe upload-artifact least common ancestor comes from your search paths, not your matched files. upload-pages-artifact pathAn actions/upload-pages-artifact path does not exist failure comes from tar, not the upload.

Permissions and secrets

GITHUB_TOKEN, OIDC, environments.

"AADSTS70021: No matching federated identity record"aadsts70021 no matching federated identity record found shares its sentence with two other codes. "deployment failed" on github-pagesAn actions/deploy-pages deployment failed at one of three gates, and each gate prints a different line. "Username and password required"docker/login-action Username and password required means both values were empty. "denied to github-actions[bot]"A GitHub Actions checkout persisted credentials push 403 reuses the credential checkout wrote into git "Unrecognized named-value: 'secrets'"A GitHub Actions composite action cannot access secrets: the parser has no such name in that file. Environment secrets read as emptyGitHub Actions environment secrets empty is not an outage. Environment secrets are read per job, and only for "denied: installation not allowed"A GitHub Actions ghcr.io push denied error names the app installation, not you. "remote: Repository not found."When a GitHub Actions GITHUB_TOKEN cannot access another repository, GitHub answers as though it did not The block is in the wrong placeA GitHub Actions id-token write permission not granted issue is about placement. "Input required and not supplied: token"GitHub Actions input required and not supplied: token is a library check on a variable. Job held by a protection ruleA GitHub Actions job waiting for review is held by a protection rule, not failing. "Failed to get ID Token."github actions oidc failed to get id token is the HTTP branch of the toolkit client. "Pull Request is not mergeable"GitHub Actions Pull Request is not mergeable appears as a step error and as a timeline event, and the two Every secret resolves to ""GitHub Actions secrets empty in fork pull requests is a documented rule with no error of its own. "1 workflow awaiting approval"GitHub Actions waiting for approval to run workflows is a policy holding a run before dispatch. "denied to github-actions[bot]"GITHUB_TOKEN read-only on fork pull requests is a documented default, not a broken permissions block. "Failed to generate ... federated token"A google-github-actions/auth workload identity audience failure is the first leg, inside the step, and the "Error 403: Resource not accessible"ncipollo/release-action 403 on release create means the token arrived and was refused, not that it was "Unable to acquire impersonated credentials"OIDC GCP Unable to acquire impersonated credentials is raised by a Google library after the auth step passed. "not permitted to create or approve"A peter-evans/create-pull-request 403 usually arrives after the branch pushed, which narrows it to one "not accessible by personal access token"Resource not accessible by personal access token means one permission is missing, not the repository. "secrets: inherit" forwards nothingsecrets: inherit not working in reusable workflows has two shapes: one fails the run at startup, the other is "Validation Failed: already_exists"A softprops/action-gh-release already_exists failure is a race between two jobs on one tag, not a refusal to "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL"Unable to get ACTIONS_ID_TOKEN_REQUEST_URL is thrown by the toolkit before any network call, because the

Runners and actions

Setup actions, third-party actions, runner selection.

Explore other topics