Expected behavior
The documented relative path works from the caller repository.
custom-security-scan-instructions: .github/custom-security-categories.txt
Current behavior
The composite action changes its working directory to github.action_path before it starts claudecode/github_action_audit.py. The Python process checks Path(scan_file).exists() and opens the input without resolving it against REPO_PATH or GITHUB_WORKSPACE. A relative caller path therefore resolves inside the action repository and is silently ignored.
Minimal reproduction
- Add
.github/custom-security-categories.txt to the caller repository.
- Pass that relative path as shown in
docs/custom-security-scan-instructions.md.
- Run the action.
- The log does not contain
Loaded custom security scan instructions.
An absolute ${{ github.workspace }}/.github/custom-security-categories.txt path works.
Either resolve relative input paths against REPO_PATH, or update the documentation and examples to require ${{ github.workspace }}. Failing when a nonempty configured path does not exist would also prevent silent loss of the security policy.
Expected behavior
The documented relative path works from the caller repository.
Current behavior
The composite action changes its working directory to
github.action_pathbefore it startsclaudecode/github_action_audit.py. The Python process checksPath(scan_file).exists()and opens the input without resolving it againstREPO_PATHorGITHUB_WORKSPACE. A relative caller path therefore resolves inside the action repository and is silently ignored.Minimal reproduction
.github/custom-security-categories.txtto the caller repository.docs/custom-security-scan-instructions.md.Loaded custom security scan instructions.An absolute
${{ github.workspace }}/.github/custom-security-categories.txtpath works.Either resolve relative input paths against
REPO_PATH, or update the documentation and examples to require${{ github.workspace }}. Failing when a nonempty configured path does not exist would also prevent silent loss of the security policy.