# Commit Output from actions/checkout: How to Capture and Use the Exact SHA

> Learn how to capture and use the exact commit SHA from actions/checkout. Access the full 40-character SHA directly in your GitHub Actions workflows for precise control.

- Repository: [GitHub Actions/checkout](https://github.com/actions/checkout)
- Tags: how-to-guide
- Published: 2026-07-18

---

**The `actions/checkout` action exposes a `commit` output containing the full 40-character SHA-1 hash of the checked out commit, accessible via `steps.<id>.outputs.commit` in subsequent workflow steps.**

The official `actions/checkout` action is the standard way to clone repositories in GitHub Actions workflows. Beyond simply fetching code, it provides valuable outputs including the precise commit SHA that was checked out. Understanding how to access and leverage this **commit output from actions/checkout** enables you to create traceable builds, tag container images, and pass version metadata to downstream automation.

## What Is the Commit Output from actions/checkout?

### Understanding the Output Definition

According to the [`action.yml`](https://github.com/actions/checkout/blob/main/action.yml) metadata file, the action declares two primary outputs: `ref` and `commit`. While `ref` indicates the branch, tag, or SHA that was requested, the `commit` output contains the actual full SHA-1 hash that the runner's working directory now points to.

### Where the Value Originates

In [`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts), the action captures the commit SHA by executing `git log1 '--format=%H'` immediately after checkout. This command returns the 40-character hash of HEAD, which is then exposed to the workflow via `core.setOutput('commit')` as implemented around lines 304-305.

## How the Commit SHA Is Generated

The action follows a precise sequence to ensure accuracy even with shallow fetches:

- **Fetch the ref** – Determines the target based on the `ref` input or triggering event.
- **Clone or fetch** – Performs a shallow or full clone depending on `fetch-depth`.
- **Checkout** – Switches to the requested ref using `git checkout`.
- **Capture the SHA** – Executes `git log1 '--format=%H'` through the [`git-command-manager.ts`](https://github.com/actions/checkout/blob/main/git-command-manager.ts) wrapper to obtain the exact commit hash.

This implementation guarantees that the output reflects the actual commit in the working directory, not just the input reference.

## How to Use the Commit Output in Your Workflow

To access the commit SHA, assign an `id` to your checkout step and reference `steps.<id>.outputs.commit` in subsequent steps.

### Example: Docker Image Tagging

```yaml
name: Build & Publish
on:
  push:
    branches: [main]

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        id: checkout
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Build Docker image
        run: |
          IMAGE_TAG=${{ steps.checkout.outputs.commit }}
          docker build -t myapp:${IMAGE_TAG} .
          docker push myapp:${IMAGE_TAG}

```

### Using the Output in Composite Actions

When building reusable composite actions, you can forward the commit output by declaring it in the outputs section:

```yaml

# .github/actions/my-composite/action.yml

name: my-composite
outputs:
  commit:
    description: 'Commit SHA from checkout'
    value: ${{ steps.checkout.outputs.commit }}
runs:
  using: composite
  steps:
    - uses: actions/checkout@v4
      id: checkout
    - run: echo "Checked out ${{ steps.checkout.outputs.commit }}"

```

## Summary

- The `commit` output provides the full 40-character SHA-1 of the checked out commit.
- It is defined in [`action.yml`](https://github.com/actions/checkout/blob/main/action.yml) and set in [`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts) via `core.setOutput`.
- Access it using `steps.<step-id>.outputs.commit` in workflow steps.
- Works with both full and shallow clones (`fetch-depth: 1`).
- Ideal for Docker image tagging, audit logs, and downstream workflow triggers.

## Frequently Asked Questions

### What is the difference between the `ref` and `commit` outputs?

The `ref` output indicates the branch, tag, or SHA that was requested for checkout, while the `commit` output always contains the resolved full SHA-1 hash of the actual commit now present in the working directory. When you request a branch name like `main`, `ref` shows "main" but `commit` shows the specific SHA.

### Does the commit output work with shallow clones?

Yes. Even when using `fetch-depth: 1` for shallow clones, the `commit` output correctly returns the SHA of the single fetched commit. The action runs `git log1` after checkout to capture the exact hash, ensuring the output is accurate regardless of fetch depth.

### How can I use the commit output in a different job?

Outputs are scoped to individual jobs. To use the commit SHA across jobs, use the `outputs` keyword at the job level to expose it, or write the value to a file and upload it as an artifact for downstream jobs to consume.

### Is the commit output available in actions/checkout v3 and v4?

Yes, the `commit` output has been available since earlier versions and is fully supported in both v3 and v4 of the action, implemented in the same [`git-source-provider.ts`](https://github.com/actions/checkout/blob/main/git-source-provider.ts) logic.