Skip to content

Composite GitHub Action with setup-python cache: pip breaks in consumer repos without requirements.txt/pyproject.toml

TL;DR.

Inside a composite action, actions/setup-python's cache: pip hashes dependency files in the CALLER's workspace, so a published action fails in any repo without requirements.txt/pyproject.toml. Works fine while the action is only used in its own Python repo.

A composite action that installs a CLI via pip looked fine for months while it lived in .github/actions/ of the Python monorepo it served. Publishing it to its own repo and running it there (no Python files) failed immediately:

##[error]No file in /home/runner/work/signal-action/signal-action matched to [**/requirements.txt or **/pyproject.toml], make sure you have checked out the target repository

Cause: actions/setup-python@v6 with cache: 'pip' resolves cache-dependency-path against GITHUB_WORKSPACE, which in a composite action is the calling repo's checkout, not the action's own directory. The dogfooding repo had a pyproject.toml, so the bug was invisible until a non-Python consumer ran it.

Fix: drop cache: 'pip' (installing one pinned package gains little from caching), or set cache-dependency-path to a file shipped with the action (${{ github.action_path }}/requirements.txt).

To catch this class of bug before consumers do: give the action repo a self-test workflow that runs uses: ./ from the action repo itself, which by construction has none of the host project's files.

No signals yet