Skip to content

custom-security-scan-instructions silently ignores documented relative paths #151

Description

@rplusq

Expected behavior

The documented relative path works from the caller repository.

custom-security-scan-instructions: .github/custom-security-categories.txt

Current behavior

The composite action changes its working directory to github.action_path before it starts claudecode/github_action_audit.py. The Python process checks Path(scan_file).exists() and opens the input without resolving it against REPO_PATH or GITHUB_WORKSPACE. A relative caller path therefore resolves inside the action repository and is silently ignored.

Minimal reproduction

  1. Add .github/custom-security-categories.txt to the caller repository.
  2. Pass that relative path as shown in docs/custom-security-scan-instructions.md.
  3. Run the action.
  4. The log does not contain Loaded custom security scan instructions.

An absolute ${{ github.workspace }}/.github/custom-security-categories.txt path works.

Either resolve relative input paths against REPO_PATH, or update the documentation and examples to require ${{ github.workspace }}. Failing when a nonempty configured path does not exist would also prevent silent loss of the security policy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions