denoland/deno · error · anyhow::Error

GITHUB_RUN_ID environment variable is not set

Error message

GITHUB_RUN_ID environment variable is not set

What it means

Provenance predicate construction reads `GITHUB_RUN_ID` (used for the run details) and throws this message when it is unset. As with the sibling variable checks, it always exists on genuine runners, so the error points to an environment that is missing parts of the Actions context.

Source

Thrown at cli/tools/publish/provenance.rs:190

    {
      let (path, ref_) = rel_ref.split_at(delimn);
      (path, &ref_[1..])
    } else {
      (rel_ref.as_str(), "")
    };

    let server_url = std::env::var("GITHUB_SERVER_URL").map_err(|_| {
      anyhow!("GITHUB_SERVER_URL environment variable is not set")
    })?;
    let github_ref = std::env::var("GITHUB_REF")
      .map_err(|_| anyhow!("GITHUB_REF environment variable is not set"))?;
    let github_sha = std::env::var("GITHUB_SHA")
      .map_err(|_| anyhow!("GITHUB_SHA environment variable is not set"))?;
    let runner_env = std::env::var("RUNNER_ENVIRONMENT").map_err(|_| {
      anyhow!("RUNNER_ENVIRONMENT environment variable is not set")
    })?;
    let run_id = std::env::var("GITHUB_RUN_ID")
      .map_err(|_| anyhow!("GITHUB_RUN_ID environment variable is not set"))?;
    let run_attempt = std::env::var("GITHUB_RUN_ATTEMPT").map_err(|_| {
      anyhow!("GITHUB_RUN_ATTEMPT environment variable is not set")
    })?;

    Ok(Self {
      build_definition: BuildDefinition {
        build_type: GITHUB_BUILD_TYPE,
        external_parameters: ExternalParameters {
          workflow: GhaWorkflow {
            ref_: workflow_ref.to_string(),
            repository: format!("{}/{}", server_url, &repo),
            path: workflow_path.to_string(),
          },
        },
        internal_parameters: InternalParameters {
          github: GithubInternalParameters {
            event_name: std::env::var("GITHUB_EVENT_NAME").unwrap_or_default(),
            repository_id: std::env::var("GITHUB_REPOSITORY_ID")

View on GitHub (pinned to 89f33cbef2)

Solutions

  1. Forward GITHUB_RUN_ID together with the full runner environment
  2. Run publish directly on the GitHub Actions runner
  3. Drop `--provenance` outside GitHub Actions
Defensive patterns

Strategy: validation

Validate before calling

if [ -z "$GITHUB_RUN_ID" ]; then
  echo "GITHUB_RUN_ID unset — publish --provenance needs the full Actions env" >&2
  exit 1
fi

Prevention

When it happens

Trigger: `deno publish --provenance` in a process where earlier variables were forwarded but GITHUB_RUN_ID was not.

Common situations: Selective env forwarding into containers; scripts that whitelist a few variables by hand.

Related errors


AI-assisted analysis of denoland/deno@89f33cbef2 (2026-08-16). Data as JSON: /api/errors/43cf9cce1973240d. Report an issue: GitHub.