Skip to content
Latchkey

GitHub Actions pipeline failure hidden without pipefail (custom shell)

The default bash shell sets pipefail, so a failing command in a pipe fails the step. Overriding shell (for example shell: bash -e {0} without -o pipefail) drops pipefail and hides upstream failures.

What this error means

A pipeline like cmd1 | cmd2 reports success even though cmd1 failed, because a custom shell setting removed pipefail.

github-actions
# step "passes" even though build fails, because cmd2 succeeds:
shell: bash -e {0}
run: ./build.sh | tee build.log

Diagnose it: print the context before you change anything

Most workflow-expression bugs are not syntax errors, they are an expression reading something that is empty. GitHub resolves a missing property to an empty string instead of failing the run, so a wrong reference looks like a logic bug rather than a mistake. Dump the contexts first and you will usually see the answer immediately.

.github/workflows/ci.yml
- name: Dump contexts
  run: |
    echo '--- github ---'   ; echo '${{ toJSON(github) }}'
    echo '--- needs ---'    ; echo '${{ toJSON(needs) }}'
    echo '--- steps ---'    ; echo '${{ toJSON(steps) }}'
    echo '--- matrix ---'   ; echo '${{ toJSON(matrix) }}'
    echo '--- inputs ---'   ; echo '${{ toJSON(inputs) }}'

Check the context is allowed where you used it

Contexts are not available everywhere. The same expression can be valid in a step if and invalid in a job if, which is why an expression that works in one workflow fails when moved.

Where you wrote itContexts available there
run-namegithub, inputs, vars
concurrencygithub, inputs, vars
Top-level envgithub, secrets, inputs, vars
jobs.<id>.ifgithub, needs, vars, inputs
jobs.<id>.steps.ifgithub, needs, strategy, matrix, job, runner, env, vars, steps, inputs
jobs.<id>.outputsFull access, including secrets
Reusable workflow outputsgithub, jobs, vars, inputs

Common causes

Custom shell drops pipefail

Overriding shell without -o pipefail evaluates only the last command status.

Relying on default but using a different shell

sh or another shell may not enable pipefail by default.

How to fix it

Restore pipefail

  1. Use the default bash shell, which already sets pipefail.
  2. If you override shell, include -o pipefail.
  3. Verify a failing left side of a pipe fails the step.
.github/workflows/ci.yml
- shell: bash
  run: |
    set -o pipefail
    ./build.sh | tee build.log

Catch it before it reaches CI

Every failure in this cluster is statically detectable. actionlint parses workflow expressions, checks context availability against the same rules above, and validates needs references, so these bugs never need to cost you a run.

Terminal
# one-off
docker run --rm -v "$(pwd):/repo" --workdir /repo rhysd/actionlint:latest -color

# as a job, before anything expensive runs
- uses: actions/checkout@v4
- run: |
    bash <(curl -s https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
    ./actionlint -color

How to prevent it

  • Prefer the default shell unless you have a specific reason to override it.
  • Always include -o pipefail when customizing the shell.

Frequently asked questions

What causes GitHub Actions pipeline failure hidden without pipefail (custom shell)?
There are 2 common causes: custom shell drops pipefail and relying on default but using a different shell. Overriding shell without -o pipefail evaluates only the last command status.
How do I fix GitHub Actions pipeline failure hidden without pipefail (custom shell)?
Restore pipefail. Use the default bash shell, which already sets pipefail.
What does GitHub Actions pipeline failure hidden without pipefail (custom shell) actually mean?
A pipeline like cmd1 | cmd2 reports success even though cmd1 failed, because a custom shell setting removed pipefail.
How do I stop GitHub Actions pipeline failure hidden without pipefail (custom shell) happening again?
Prefer the default shell unless you have a specific reason to override it. The prevention section lists 2 changes that keep it from recurring.

Related guides

References

Not every red build is your code. Latchkey repairs the ones that are not, on the runner. Start free → 30-day trial · No credit card