Context
GitHub Actions jobs can call reusable workflows in another repository with owner/repository/.github/workflows/file@ref. Issue #23 covers only repository-local calls such as ./.github/workflows/file.yaml.
Open Actions has no job-level reusable-workflow call model, so cross-repository workflow libraries cannot be used.
Goal
Call reusable workflows from other repositories with GitHub-compatible resolution, access, input, secret, permission, output, and nesting behavior.
Acceptance criteria
- Parse the documented cross-repository job-level
uses, with, secrets, permissions, needs, if, and concurrency combinations.
- Resolve the called workflow only from
.github/workflows at the requested commit, tag, or branch with GitHub-compatible ref precedence.
- Authenticate private workflow downloads without exposing the download credential to called jobs.
- Validate
workflow_call inputs and secrets and implement explicit and inherited secret passing within GitHub organization and repository boundaries.
- Prevent the called workflow from elevating the caller token permissions and apply nested permission narrowing.
- Return called-workflow outputs and results to the caller job.
- Match documented nesting, unique-workflow, loop-detection, rerun, and reference-pinning behavior.
- Preserve the documented caller and called-workflow context values, including workflow reference and SHA properties.
- Add end-to-end tests for public and private repositories, SHA and moving refs, nested calls, permission reduction, secret boundaries, outputs, loops, inaccessible repositories, and reruns.
- Document required GitHub App repository access and recommend immutable commit SHAs for trust-sensitive calls.
References:
Context
GitHub Actions jobs can call reusable workflows in another repository with
owner/repository/.github/workflows/file@ref. Issue #23 covers only repository-local calls such as./.github/workflows/file.yaml.Open Actions has no job-level reusable-workflow call model, so cross-repository workflow libraries cannot be used.
Goal
Call reusable workflows from other repositories with GitHub-compatible resolution, access, input, secret, permission, output, and nesting behavior.
Acceptance criteria
uses,with,secrets,permissions,needs,if, and concurrency combinations..github/workflowsat the requested commit, tag, or branch with GitHub-compatible ref precedence.workflow_callinputs and secrets and implement explicit and inherited secret passing within GitHub organization and repository boundaries.References: