GitHub Actions "a step cannot have both the uses and run keys"
A step is either an action (uses) or a shell command (run), never both. Declaring uses and run in the same step is ambiguous and rejected at parse time.
What this error means
The workflow fails to start with "a step cannot have both the uses and run keys", pointing at a step that declares both.
Error: a step cannot have both the `uses` and `run` keysDiagnose it: print the context before you change anything
Most workflow-expression bugs are not syntax errors, they are an expression reading something that is empty. GitHub resolves a missing property to an empty string instead of failing the run, so a wrong reference looks like a logic bug rather than a mistake. Dump the contexts first and you will usually see the answer immediately.
- name: Dump contexts
run: |
echo '--- github ---' ; echo '${{ toJSON(github) }}'
echo '--- needs ---' ; echo '${{ toJSON(needs) }}'
echo '--- steps ---' ; echo '${{ toJSON(steps) }}'
echo '--- matrix ---' ; echo '${{ toJSON(matrix) }}'
echo '--- inputs ---' ; echo '${{ toJSON(inputs) }}'Check the context is allowed where you used it
Contexts are not available everywhere. The same expression can be valid in a step if and invalid in a job if, which is why an expression that works in one workflow fails when moved.
| Where you wrote it | Contexts available there |
|---|---|
run-name | github, inputs, vars |
concurrency | github, inputs, vars |
Top-level env | github, secrets, inputs, vars |
jobs.<id>.if | github, needs, vars, inputs |
jobs.<id>.steps.if | github, needs, strategy, matrix, job, runner, env, vars, steps, inputs |
jobs.<id>.outputs | Full access, including secrets |
Reusable workflow outputs | github, jobs, vars, inputs |
Common causes
Merged two steps into one
An action step and a command step were accidentally combined under a single list item.
Indentation collapsed two steps
Wrong YAML indentation made a run line attach to a uses step.
How to fix it
Split into separate steps
- Put the action in its own step with uses.
- Put the command in a separate step with run.
- Fix indentation so each is a distinct list item.
steps:
- uses: actions/checkout@v4
- run: npm ci && npm testCatch it before it reaches CI
Every failure in this cluster is statically detectable. actionlint parses workflow expressions, checks context availability against the same rules above, and validates needs references, so these bugs never need to cost you a run.
# one-off
docker run --rm -v "$(pwd):/repo" --workdir /repo rhysd/actionlint:latest -color
# as a job, before anything expensive runs
- uses: actions/checkout@v4
- run: |
bash <(curl -s https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
./actionlint -colorHow to prevent it
- Keep one action or one command per step, never both.
- Watch step indentation so lines do not merge.
- Lint workflows to catch uses+run on one step.