certslothcertsloth
GH-200/Topic 03

GitHub / Associate

Outputs, Artifacts, Caches and Summaries

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Outputs carry small values; artifacts carry deliverables; caches save repeat work.

Must remember

Write step outputs through GITHUB_OUTPUT, then map them to job outputs for dependent jobs using needs. GITHUB_ENV sets environment values for later steps in the same job; the writing step must still use its local value normally. Use correct multiline delimiters and do not place secrets in public outputs or summaries.

Artifacts persist selected files such as build products and test reports across jobs/runs under retention policies. Upload only intended paths; broad directory uploads can leak credentials or source data. An artifact's name is not proof of origin or integrity. Verify digest/provenance where the deployment trust model requires it.

Caches speed repeat dependency/build work. Keys should reflect relevant OS, toolchain and lockfile inputs; restore-key fallback can retrieve less exact matches. A cache miss should slow a correct build rather than make it impossible. Never treat caches as durable release storage or a safe place for secrets.

GITHUB_STEP_SUMMARY adds Markdown to the run's job summary. Keep reports concise and link appropriate artifacts/logs. Status badges show workflow status for a configured branch/event; they are not evidence that a particular production deployment passed.

Manage retention at supported repository/organization levels and through appropriate APIs for logs, runs and artifacts. Short retention saves storage but can remove incident/debug evidence. Set environment protections for deployment jobs and preserve the exact built artifact through promotion instead of silently rebuilding different bytes for production.

Choose under exam pressure

Requirement Choice and reason
Pass a version string to a dependent job Step output mapped to job output.
Keep a test report for review Artifact with deliberate retention.
Avoid re-downloading unchanged dependencies Cache keyed by relevant dependency/toolchain inputs.

Traps

  • A cache is not a release archive.
  • The step writing GITHUB_ENV does not magically re-read its environment.

Active recall

1. How do jobs exchange a small computed value?

Expose a job output and read it through needs.

2. Artifact versus cache?

Retained output for use/review versus optional acceleration of repeat work.

3. Why narrow upload paths?

To avoid leaking unrelated or sensitive files.

4. What belongs in a job summary?

Readable results and links, excluding secrets.

5. Why promote the same artifact?

To deploy the exact bytes that were tested and verified.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.