Skip to content

Support cross-repository reusable workflow calls #119

Description

@gjkim42

Context

GitHub Actions jobs can call reusable workflows in another repository with owner/repository/.github/workflows/file@ref. Issue #23 covers only repository-local calls such as ./.github/workflows/file.yaml.

Open Actions has no job-level reusable-workflow call model, so cross-repository workflow libraries cannot be used.

Goal

Call reusable workflows from other repositories with GitHub-compatible resolution, access, input, secret, permission, output, and nesting behavior.

Acceptance criteria

  • Parse the documented cross-repository job-level uses, with, secrets, permissions, needs, if, and concurrency combinations.
  • Resolve the called workflow only from .github/workflows at the requested commit, tag, or branch with GitHub-compatible ref precedence.
  • Authenticate private workflow downloads without exposing the download credential to called jobs.
  • Validate workflow_call inputs and secrets and implement explicit and inherited secret passing within GitHub organization and repository boundaries.
  • Prevent the called workflow from elevating the caller token permissions and apply nested permission narrowing.
  • Return called-workflow outputs and results to the caller job.
  • Match documented nesting, unique-workflow, loop-detection, rerun, and reference-pinning behavior.
  • Preserve the documented caller and called-workflow context values, including workflow reference and SHA properties.
  • Add end-to-end tests for public and private repositories, SHA and moving refs, nested calls, permission reduction, secret boundaries, outputs, loops, inaccessible repositories, and reruns.
  • Document required GitHub App repository access and recommend immutable commit SHAs for trust-sensitive calls.

References:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions