Commit Output from actions/checkout: How to Capture and Use the Exact SHA

The actions/checkout action exposes a commit output containing the full 40-character SHA-1 hash of the checked out commit, accessible via steps.<id>.outputs.commit in subsequent workflow steps.

The official actions/checkout action is the standard way to clone repositories in GitHub Actions workflows. Beyond simply fetching code, it provides valuable outputs including the precise commit SHA that was checked out. Understanding how to access and leverage this commit output from actions/checkout enables you to create traceable builds, tag container images, and pass version metadata to downstream automation.

What Is the Commit Output from actions/checkout?

Understanding the Output Definition

According to the action.yml metadata file, the action declares two primary outputs: ref and commit. While ref indicates the branch, tag, or SHA that was requested, the commit output contains the actual full SHA-1 hash that the runner's working directory now points to.

Where the Value Originates

In src/git-source-provider.ts, the action captures the commit SHA by executing git log1 '--format=%H' immediately after checkout. This command returns the 40-character hash of HEAD, which is then exposed to the workflow via core.setOutput('commit') as implemented around lines 304-305.

How the Commit SHA Is Generated

The action follows a precise sequence to ensure accuracy even with shallow fetches:

  • Fetch the ref – Determines the target based on the ref input or triggering event.
  • Clone or fetch – Performs a shallow or full clone depending on fetch-depth.
  • Checkout – Switches to the requested ref using git checkout.
  • Capture the SHA – Executes git log1 '--format=%H' through the git-command-manager.ts wrapper to obtain the exact commit hash.

This implementation guarantees that the output reflects the actual commit in the working directory, not just the input reference.

How to Use the Commit Output in Your Workflow

To access the commit SHA, assign an id to your checkout step and reference steps.<id>.outputs.commit in subsequent steps.

Example: Docker Image Tagging

name: Build & Publish
on:
  push:
    branches: [main]

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        id: checkout
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Build Docker image
        run: |
          IMAGE_TAG=${{ steps.checkout.outputs.commit }}
          docker build -t myapp:${IMAGE_TAG} .
          docker push myapp:${IMAGE_TAG}

Using the Output in Composite Actions

When building reusable composite actions, you can forward the commit output by declaring it in the outputs section:


# .github/actions/my-composite/action.yml

name: my-composite
outputs:
  commit:
    description: 'Commit SHA from checkout'
    value: ${{ steps.checkout.outputs.commit }}
runs:
  using: composite
  steps:
    - uses: actions/checkout@v4
      id: checkout
    - run: echo "Checked out ${{ steps.checkout.outputs.commit }}"

Summary

  • The commit output provides the full 40-character SHA-1 of the checked out commit.
  • It is defined in action.yml and set in src/git-source-provider.ts via core.setOutput.
  • Access it using steps.<step-id>.outputs.commit in workflow steps.
  • Works with both full and shallow clones (fetch-depth: 1).
  • Ideal for Docker image tagging, audit logs, and downstream workflow triggers.

Frequently Asked Questions

What is the difference between the ref and commit outputs?

The ref output indicates the branch, tag, or SHA that was requested for checkout, while the commit output always contains the resolved full SHA-1 hash of the actual commit now present in the working directory. When you request a branch name like main, ref shows "main" but commit shows the specific SHA.

Does the commit output work with shallow clones?

Yes. Even when using fetch-depth: 1 for shallow clones, the commit output correctly returns the SHA of the single fetched commit. The action runs git log1 after checkout to capture the exact hash, ensuring the output is accurate regardless of fetch depth.

How can I use the commit output in a different job?

Outputs are scoped to individual jobs. To use the commit SHA across jobs, use the outputs keyword at the job level to expose it, or write the value to a file and upload it as an artifact for downstream jobs to consume.

Is the commit output available in actions/checkout v3 and v4?

Yes, the commit output has been available since earlier versions and is fully supported in both v3 and v4 of the action, implemented in the same git-source-provider.ts logic.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →