certslothcertsloth
GH-200/Topic 06

GitHub / Associate

Custom Actions, Metadata and Releases

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: The action is a product with an interface and a supply chain.

Must remember

JavaScript actions run the supported runtime declared in action metadata. Docker container actions package an execution environment and require a compatible runner platform. Composite actions combine steps and require explicit shell/working-directory handling where appropriate. Choose based on portability, dependency isolation and maintenance needs.

An action uses action.yml or action.yaml to declare name, description, inputs, outputs and runs behavior. Metadata defaults and required declarations do not replace runtime validation for every input path. Document side effects and permissions, return useful errors and avoid logging secrets.

Workflow commands and environment files communicate outputs, annotations, path changes and summaries. Untrusted output must not be allowed to impersonate control instructions or inject shell code. A Docker action needs intentional entrypoint/argument behavior; a JavaScript action needs packaged runtime dependencies so consumers are not dependent on a developer's local node_modules.

Test supported operating systems, runtimes, failure paths and upgrade behavior. The chosen JavaScript runtime and minimum runner compatibility evolve; follow current action metadata/runtime documentation. A composite step can fail because a tool exists on one image but not another.

Distribute privately, publicly or through Marketplace as appropriate. Publish clear versions and changelogs. A full commit SHA identifies source precisely; floating major tags offer convenient updates but can change. Where immutable release/action mechanisms apply, understand their guarantees and compatibility rather than assuming every tag is immutable. Consumers should verify source, permissions and provenance before executing it.

Choose under exam pressure

Requirement Choice and reason
Cross-platform logic using a supported JS runtime JavaScript action.
Controlled Linux container environment Docker action on compatible runners.
Reuse existing shell/actions steps Composite action.

Traps

  • Marketplace publication is not a security audit.
  • An action that worked on a developer laptop may omit needed packaged dependencies.

Active recall

1. What defines an action interface?

Its metadata, documented inputs/outputs, permissions and behavior.

2. Why validate inputs in code?

Metadata cannot guarantee every runtime assumption or prevent malicious values.

3. Why check runner compatibility?

Action runtime and container features require supported runner capabilities.

4. SHA versus floating tag?

A specific source revision versus a name whose target can change.

5. What should release notes communicate?

Behavior changes, compatibility requirements, fixes and migration steps.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.