github / github/docs

Documentation bug: expression numbers are mis-documented

Open
#43,008 11 comments 1 reaction 0 assignees View on GitHub
builder persona content github_actions never-stale
Dominant language
TypeScript
Stars
20.8k
Forks
68.7k
Avg merge
13h 17m
Merged PRs (30d)
110

Description

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

The "Literals" section of the GitHub Actions expression syntax page:

https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#literals

That link is for the "Free, Pro, and Teams" page, but the GHES and GHEC pages are also affected.

### What part(s) of the article would you like to see updated?

The `number` literal is documented as "Any number format supported by JSON." However, in reality, the GitHub Actions expression parser takes a much larger set of literals, which it coerces to numbers.

For example, neither hex nor octal literals are valid in JSON, but GitHub Actions accepts them. For example:

```
${{ 0xff }}
${{ 0o777 }}
```

More generally, GitHub Actions appears to support any number literal that the JavaScript `Number(...)` constructor can coerce a string from. Those coercion rules are documented here:

https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Number#number_coercion

This can be seen in the official GitHub Actions expression parser, which appears to use the `Number(...)` constructor when turning a `StringData` lexeme into a number:

https://github.com/actions/languageservices/blob/fb5c6e4f27bb1ddf512609a6a341aadd17ce86f3/expressions/src/data/string.ts#L14-L16

### Additional information

Yes, this is trivially reproducible in any GitHub Actions workflow or action definition.

See https://github.com/zizmorcore/zizmor/pull/1628 for a related downstream report.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.