Concept and mechanism
A workflow has several data boundaries. A local variable belongs to the shell process. Writing to GITHUB_ENV makes a value available to subsequent steps in the same job without automatically changing the shell that wrote it. Across jobs, an identified step publishes an output, the job maps that result, and the consumer uses needs. Scalar values and files use different channels: a digest can be an output, while the corresponding binary should travel as an identified artifact. Never turn outputs or logs into an improvised credential channel. The contract should describe name, meaning, origin, and handling of missing values.
Guided application
In a fictional reporting rehearsal, build produces a digest and deploy compares it with the approved candidate before promotion. If the value arrives empty, inspect the step write, its ID, the job mapping, and the consumer reference. Do not replace a missing value with implicit approval. For PostgreSQL tests, identify where the client runs: inside the job container, the service name reaches the database container; localhost identifies the job container itself. A job directly on the runner uses the published-port design for that case. YAML anchors and aliases reduce repetition within the document but do not constitute centralized policy distribution across repositories.
Client inside the job container: postgres:5432. Host client: confirm the published port.
Common pitfalls
Env as global; unmapped output; universal localhost; YAML alias as distributed policy.
Related topics: Events, filters, and dependencies · Reuse, artifacts, and troubleshooting · Actions with contracts and versions
Locate each value’s producer, boundary, and consumer.
Reference: Workflow commands · GH-200 skills measured January2026;study guide updated2026-02-05