{"id":13479644,"url":"https://github.com/actions/upload-artifact","last_synced_at":"2025-09-09T20:38:59.089Z","repository":{"id":38689762,"uuid":"192625955","full_name":"actions/upload-artifact","owner":"actions","description":null,"archived":false,"fork":false,"pushed_at":"2025-07-25T11:27:48.000Z","size":11542,"stargazers_count":3668,"open_issues_count":220,"forks_count":903,"subscribers_count":75,"default_branch":"main","last_synced_at":"2025-08-21T13:50:16.988Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/actions.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2019-06-18T23:36:34.000Z","updated_at":"2025-08-21T08:28:44.000Z","dependencies_parsed_at":"2024-01-22T22:13:19.276Z","dependency_job_id":"2e9f7662-efdd-4f6a-a348-c40537a86703","html_url":"https://github.com/actions/upload-artifact","commit_stats":{"total_commits":195,"total_committers":42,"mean_commits":4.642857142857143,"dds":0.7384615384615385,"last_synced_commit":"6f51ac03b9356f520e9adb1b1b7802705f340c2b"},"previous_names":[],"tags_count":48,"template":false,"template_full_name":null,"purl":"pkg:github/actions/upload-artifact","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/actions%2Fupload-artifact","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/actions%2Fupload-artifact/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/actions%2Fupload-artifact/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/actions%2Fupload-artifact/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/actions","download_url":"https://codeload.github.com/actions/upload-artifact/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/actions%2Fupload-artifact/sbom","scorecard":{"id":163800,"data":{"date":"2025-08-11","repo":{"name":"github.com/actions/upload-artifact","commit":"de65e23aa2b7e23d713bb51fbfcb6d502f8667d8"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.8,"checks":[{"name":"Maintained","score":1,"reason":"2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'packages' permission set to 'write': .github/workflows/publish-immutable-actions.yml:13","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-immutable-actions.yml:11","Warn: no topLevel permission defined: .github/workflows/check-dist.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Warn: no topLevel permission defined: .github/workflows/licensed.yml:1","Warn: no topLevel permission defined: .github/workflows/publish-immutable-actions.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-new-action-version.yml:14","Warn: no topLevel permission defined: .github/workflows/test.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-dist.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/check-dist.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-dist.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/check-dist.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-dist.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/check-dist.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/licensed.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/licensed.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-immutable-actions.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/publish-immutable-actions.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-immutable-actions.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/publish-immutable-actions.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-new-action-version.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/release-new-action-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:269: update your workflow using https://app.stepsecurity.io/secureworkflow/actions/upload-artifact/test.yml/main?enable=pin","Info:   0 out of  21 GitHub-owned GitHubAction dependencies pinned","Info:   3 out of   3 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":9,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/actions/.github/SECURITY.md:1","Info: Found linked content: github.com/actions/.github/SECURITY.md:1","Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy","Info: Found text in security policy: github.com/actions/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'v3/node20'","Warn: branch protection not enabled for branch 'v3/node16'","Warn: branch protection not enabled for branch 'eggyhead/use-artifact-v2.1.6'","Warn: branch protection not enabled for branch 'eggyhead/release-4.3.2'","Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Info: codeowner review is required on branch 'main'","Info: 'last push approval' is required to merge on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 27 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-c76h-2ccp-4975","Warn: Project is vulnerable to: GHSA-cxrh-j4jr-qwg3"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-16T14:18:14.704Z","repository_id":38689762,"created_at":"2025-08-16T14:18:14.704Z","updated_at":"2025-08-16T14:18:14.704Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":274358533,"owners_count":25270679,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-09T02:00:10.223Z","response_time":80,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T16:02:20.721Z","updated_at":"2025-09-09T20:38:59.077Z","avatar_url":"https://github.com/actions.png","language":"TypeScript","funding_links":[],"categories":["TypeScript","Official Resources","Others","Todo","二、核心官方Action（工作流必备）"],"sub_categories":["Official Actions","Code GPT","1. 工作流基础工具"],"readme":"# `@actions/upload-artifact`\n\n\u003e [!WARNING]\n\u003e actions/upload-artifact@v3 is scheduled for deprecation on **November 30, 2024**. [Learn more.](https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/)\n\u003e Similarly, v1/v2 are scheduled for deprecation on **June 30, 2024**.\n\u003e Please update your workflow to use v4 of the artifact actions.\n\u003e This deprecation will not impact any existing versions of GitHub Enterprise Server being used by customers.\n\nUpload [Actions Artifacts](https://docs.github.com/en/actions/using-workflows/storing-workflow-data-as-artifacts) from your Workflow Runs. Internally powered by [@actions/artifact](https://github.com/actions/toolkit/tree/main/packages/artifact) package.\n\nSee also [download-artifact](https://github.com/actions/download-artifact).\n\n- [`@actions/upload-artifact`](#actionsupload-artifact)\n  - [v4 - What's new](#v4---whats-new)\n    - [Improvements](#improvements)\n    - [Breaking Changes](#breaking-changes)\n  - [Usage](#usage)\n    - [Inputs](#inputs)\n    - [Outputs](#outputs)\n  - [Examples](#examples)\n    - [Upload an Individual File](#upload-an-individual-file)\n    - [Upload an Entire Directory](#upload-an-entire-directory)\n    - [Upload using a Wildcard Pattern](#upload-using-a-wildcard-pattern)\n    - [Upload using Multiple Paths and Exclusions](#upload-using-multiple-paths-and-exclusions)\n    - [Altering compressions level (speed v. size)](#altering-compressions-level-speed-v-size)\n    - [Customization if no files are found](#customization-if-no-files-are-found)\n    - [(Not) Uploading to the same artifact](#not-uploading-to-the-same-artifact)\n    - [Environment Variables and Tilde Expansion](#environment-variables-and-tilde-expansion)\n    - [Retention Period](#retention-period)\n    - [Using Outputs](#using-outputs)\n      - [Example output between steps](#example-output-between-steps)\n      - [Example output between jobs](#example-output-between-jobs)\n    - [Overwriting an Artifact](#overwriting-an-artifact)\n  - [Limitations](#limitations)\n    - [Number of Artifacts](#number-of-artifacts)\n    - [Zip archives](#zip-archives)\n    - [Permission Loss](#permission-loss)\n  - [Where does the upload go?](#where-does-the-upload-go)\n\n\n## v4 - What's new\n\n\u003e [!IMPORTANT]\n\u003e upload-artifact@v4+ is not currently supported on GHES yet. If you are on GHES, you must use [v3](https://github.com/actions/upload-artifact/releases/tag/v3).\n\nThe release of upload-artifact@v4 and download-artifact@v4 are major changes to the backend architecture of Artifacts. They have numerous performance and behavioral improvements.\n\nFor more information, see the [`@actions/artifact`](https://github.com/actions/toolkit/tree/main/packages/artifact) documentation.\n\nThere is also a new sub-action, `actions/upload-artifact/merge`. For more info, check out that action's [README](./merge/README.md).\n\n### Improvements\n\n1. Uploads are significantly faster, upwards of 90% improvement in worst case scenarios.\n2. Once uploaded, an Artifact ID is returned and Artifacts are immediately available in the UI and [REST API](https://docs.github.com/en/rest/actions/artifacts). Previously, you would have to wait for the run to be completed before an ID was available or any APIs could be utilized.\n3. The contents of an Artifact are uploaded together into an _immutable_ archive. They cannot be altered by subsequent jobs unless the Artifacts are deleted and recreated (where they will have a new ID). Both of these factors help reduce the possibility of accidentally corrupting Artifact files.\n4. The compression level of an Artifact can be manually tweaked for speed or size reduction.\n\n### Breaking Changes\n\n1. On self hosted runners, additional [firewall rules](https://github.com/actions/toolkit/tree/main/packages/artifact#breaking-changes) may be required.\n2. Uploading to the same named Artifact multiple times.\n\n    Due to how Artifacts are created in this new version, it is no longer possible to upload to the same named Artifact multiple times. You must either split the uploads into multiple Artifacts with different names, or only upload once. Otherwise you _will_ encounter an error.\n\n3. Limit of Artifacts for an individual job. Each job in a workflow run now has a limit of 500 artifacts.\n4. With `v4.4` and later, hidden files are excluded by default.\n\nFor assistance with breaking changes, see [MIGRATION.md](docs/MIGRATION.md).\n\n## Note\n\nThank you for your interest in this GitHub repo, however, right now we are not taking contributions. \n\nWe continue to focus our resources on strategic areas that help our customers be successful while making developers' lives easier. While GitHub Actions remains a key part of this vision, we are allocating resources towards other areas of Actions and are not taking contributions to this repository at this time. The GitHub public roadmap is the best place to follow along for any updates on features we’re working on and what stage they’re in.\n\nWe are taking the following steps to better direct requests related to GitHub Actions, including:\n\n1. We will be directing questions and support requests to our [Community Discussions area](https://github.com/orgs/community/discussions/categories/actions)\n\n2. High Priority bugs can be reported through Community Discussions or you can report these to our support team https://support.github.com/contact/bug-report.\n\n3. Security Issues should be handled as per our [security.md](SECURITY.md).\n\nWe will still provide security updates for this project and fix major breaking changes during this time.\n\nYou are welcome to still raise bugs in this repo.\n\n## Usage\n\n### Inputs\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    # Name of the artifact to upload.\n    # Optional. Default is 'artifact'\n    name:\n\n    # A file, directory or wildcard pattern that describes what to upload\n    # Required.\n    path:\n\n    # The desired behavior if no files are found using the provided path.\n    # Available Options:\n    #   warn: Output a warning but do not fail the action\n    #   error: Fail the action with an error message\n    #   ignore: Do not output any warnings or errors, the action does not fail\n    # Optional. Default is 'warn'\n    if-no-files-found:\n\n    # Duration after which artifact will expire in days. 0 means using default retention.\n    # Minimum 1 day.\n    # Maximum 90 days unless changed from the repository settings page.\n    # Optional. Defaults to repository settings.\n    retention-days:\n\n    # The level of compression for Zlib to be applied to the artifact archive.\n    # The value can range from 0 to 9.\n    # For large files that are not easily compressed, a value of 0 is recommended for significantly faster uploads.\n    # Optional. Default is '6'\n    compression-level:\n\n    # If true, an artifact with a matching name will be deleted before a new one is uploaded.\n    # If false, the action will fail if an artifact for the given name already exists.\n    # Does not fail if the artifact does not exist.\n    # Optional. Default is 'false'\n    overwrite:\n\n    # Whether to include hidden files in the provided path in the artifact\n    # The file contents of any hidden files in the path should be validated before\n    # enabled this to avoid uploading sensitive information.\n    # Optional. Default is 'false'\n    include-hidden-files:\n```\n\n### Outputs\n\n| Name | Description | Example |\n| - | - | - |\n| `artifact-id` | GitHub ID of an Artifact, can be used by the REST API | `1234` |\n| `artifact-url` | URL to download an Artifact. Can be used in many scenarios such as linking to artifacts in issues or pull requests. Users must be logged-in in order for this URL to work. This URL is valid as long as the artifact has not expired or the artifact, run or repository have not been deleted | `https://github.com/example-org/example-repo/actions/runs/1/artifacts/1234` |\n| `artifact-digest` | SHA-256 digest of an Artifact | 0fde654d4c6e659b45783a725dc92f1bfb0baa6c2de64b34e814dc206ff4aaaf |\n\n## Examples\n\n### Upload an Individual File\n\n```yaml\nsteps:\n- run: mkdir -p path/to/artifact\n- run: echo hello \u003e path/to/artifact/world.txt\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: path/to/artifact/world.txt\n```\n\n### Upload an Entire Directory\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: path/to/artifact/ # or path/to/artifact\n```\n\n### Upload using a Wildcard Pattern\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: path/**/[abc]rtifac?/*\n```\n\n### Upload using Multiple Paths and Exclusions\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: |\n      path/output/bin/\n      path/output/test-results\n      !path/**/*.tmp\n```\n\nFor supported wildcards along with behavior and documentation, see [@actions/glob](https://github.com/actions/toolkit/tree/main/packages/glob) which is used internally to search for files.\n\nIf a wildcard pattern is used, the path hierarchy will be preserved after the first wildcard pattern:\n\n```\npath/to/*/directory/foo?.txt =\u003e\n    ∟ path/to/some/directory/foo1.txt\n    ∟ path/to/some/directory/foo2.txt\n    ∟ path/to/other/directory/foo1.txt\n\nwould be flattened and uploaded as =\u003e\n    ∟ some/directory/foo1.txt\n    ∟ some/directory/foo2.txt\n    ∟ other/directory/foo1.txt\n```\n\nIf multiple paths are provided as input, the least common ancestor of all the search paths will be used as the root directory of the artifact. Exclude paths do not affect the directory structure.\n\nRelative and absolute file paths are both allowed. Relative paths are rooted against the current working directory. Paths that begin with a wildcard character should be quoted to avoid being interpreted as YAML aliases.\n\n### Altering compressions level (speed v. size)\n\nIf you are uploading large or easily compressable data to your artifact, you may benefit from tweaking the compression level. By default, the compression level is `6`, the same as GNU Gzip.\n\nThe value can range from 0 to 9:\n  - 0: No compression\n  - 1: Best speed\n  - 6: Default compression (same as GNU Gzip)\n  - 9: Best compression\n\nHigher levels will result in better compression, but will take longer to complete.\nFor large files that are not easily compressed, a value of `0` is recommended for significantly faster uploads.\n\nFor instance, if you are uploading random binary data, you can save a lot of time by opting out of compression completely, since it won't benefit:\n\n```yaml\n- name: Make a 1GB random binary file\n  run: |\n    dd if=/dev/urandom of=my-1gb-file bs=1M count=1000\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: my-1gb-file\n    compression-level: 0 # no compression\n```\n\nBut, if you are uploading data that is easily compressed (like plaintext, code, etc) you can save space and cost by having a higher compression level. But this will be heavier on the CPU therefore slower to upload:\n\n```yaml\n- name: Make a file with a lot of repeated text\n  run: |\n    for i in {1..100000}; do echo -n 'foobar' \u003e\u003e foobar.txt; done\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: foobar.txt\n    compression-level: 9 # maximum compression\n```\n\n### Customization if no files are found\n\nIf a path (or paths), result in no files being found for the artifact, the action will succeed but print out a warning. In certain scenarios it may be desirable to fail the action or suppress the warning. The `if-no-files-found` option allows you to customize the behavior of the action if no files are found:\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: path/to/artifact/\n    if-no-files-found: error # 'warn' or 'ignore' are also available, defaults to `warn`\n```\n\n### (Not) Uploading to the same artifact\n\nUnlike earlier versions of `upload-artifact`, uploading to the same artifact via multiple jobs is _not_ supported with `v4`.\n\n```yaml\n- run: echo hi \u003e world.txt\n- uses: actions/upload-artifact@v4\n  with:\n    # implicitly named as 'artifact'\n    path: world.txt\n\n- run: echo howdy \u003e extra-file.txt\n- uses: actions/upload-artifact@v4\n  with:\n    # also implicitly named as 'artifact', will fail here!\n    path: extra-file.txt\n```\n\nArtifact names must be unique since each created artifact is idempotent so multiple jobs cannot modify the same artifact.\n\nIn matrix scenarios, be careful to not accidentally upload to the same artifact, or else you will encounter conflict errors. It would be best to name the artifact _with_ a prefix or suffix from the matrix:\n\n```yaml\njobs:\n  upload:\n    name: Generate Build Artifacts\n\n    strategy:\n      matrix:\n        os: [ubuntu-latest, windows-latest]\n        version: [a, b, c]\n\n    runs-on: ${{ matrix.os }}\n\n    steps:\n    - name: Build\n      run: ./some-script --version=${{ matrix.version }} \u003e my-binary\n    - name: Upload\n      uses: actions/upload-artifact@v4\n      with:\n        name: binary-${{ matrix.os }}-${{ matrix.version }}\n        path: my-binary\n```\n\nThis will result in artifacts like: `binary-ubuntu-latest-a`, `binary-windows-latest-b`, and so on.\n\nPreviously the behavior _allowed_ for the artifact names to be the same which resulted in unexpected mutations and accidental corruption. Artifacts created by upload-artifact@v4 are immutable.\n\n### Environment Variables and Tilde Expansion\n\nYou can use `~` in the path input as a substitute for `$HOME`. Basic tilde expansion is supported:\n\n```yaml\n  - run: |\n      mkdir -p ~/new/artifact\n      echo hello \u003e ~/new/artifact/world.txt\n  - uses: actions/upload-artifact@v4\n    with:\n      name: my-artifacts\n      path: ~/new/**/*\n```\n\nEnvironment variables along with context expressions can also be used for input. For documentation see [context and expression syntax](https://help.github.com/en/actions/reference/context-and-expression-syntax-for-github-actions):\n\n```yaml\n    env:\n      name: my-artifact\n    steps:\n    - run: |\n        mkdir -p ${{ github.workspace }}/artifact\n        echo hello \u003e ${{ github.workspace }}/artifact/world.txt\n    - uses: actions/upload-artifact@v4\n      with:\n        name: ${{ env.name }}-name\n        path: ${{ github.workspace }}/artifact/**/*\n```\n\nFor environment variables created in other steps, make sure to use the `env` expression syntax\n\n```yaml\n    steps:\n    - run: |\n        mkdir testing\n        echo \"This is a file to upload\" \u003e testing/file.txt\n        echo \"artifactPath=testing/file.txt\" \u003e\u003e $GITHUB_ENV\n    - uses: actions/upload-artifact@v4\n      with:\n        name: artifact\n        path: ${{ env.artifactPath }} # this will resolve to testing/file.txt at runtime\n```\n\n### Retention Period\n\nArtifacts are retained for 90 days by default. You can specify a shorter retention period using the `retention-days` input:\n\n```yaml\n  - name: Create a file\n    run: echo \"I won't live long\" \u003e my_file.txt\n\n  - name: Upload Artifact\n    uses: actions/upload-artifact@v4\n    with:\n      name: my-artifact\n      path: my_file.txt\n      retention-days: 5\n```\n\nThe retention period must be between 1 and 90 inclusive. For more information see [artifact and log retention policies](https://docs.github.com/en/free-pro-team@latest/actions/reference/usage-limits-billing-and-administration#artifact-and-log-retention-policy).\n\n### Using Outputs\n\nIf an artifact upload is successful then an `artifact-id` output is available. This ID is a unique identifier that can be used with [Artifact REST APIs](https://docs.github.com/en/rest/actions/artifacts).\n\n#### Example output between steps\n\n```yml\n    - uses: actions/upload-artifact@v4\n      id: artifact-upload-step\n      with:\n        name: my-artifact\n        path: path/to/artifact/content/\n\n    - name: Output artifact ID\n      run:  echo 'Artifact ID is ${{ steps.artifact-upload-step.outputs.artifact-id }}'\n```\n\n#### Example output between jobs\n\n```yml\njobs:\n  job1:\n    runs-on: ubuntu-latest\n    outputs:\n      output1: ${{ steps.artifact-upload-step.outputs.artifact-id }}\n    steps:\n      - uses: actions/upload-artifact@v4\n        id: artifact-upload-step\n        with:\n          name: my-artifact\n          path: path/to/artifact/content/\n  job2:\n    runs-on: ubuntu-latest\n    needs: job1\n    steps:\n      - env:\n          OUTPUT1: ${{needs.job1.outputs.output1}}\n        run: echo \"Artifact ID from previous job is $OUTPUT1\"\n```\n\n### Overwriting an Artifact\n\nAlthough it's not possible to mutate an Artifact, can completely overwrite one. But do note that this will give the Artifact a new ID, the previous one will no longer exist:\n\n```yaml\njobs:\n  upload:\n    runs-on: ubuntu-latest\n    steps:\n      - name: Create a file\n        run: echo \"hello world\" \u003e my-file.txt\n      - name: Upload Artifact\n        uses: actions/upload-artifact@v4\n        with:\n          name: my-artifact # NOTE: same artifact name\n          path: my-file.txt\n  upload-again:\n    needs: upload\n    runs-on: ubuntu-latest\n    steps:\n      - name: Create a different file\n        run: echo \"goodbye world\" \u003e my-file.txt\n      - name: Upload Artifact\n        uses: actions/upload-artifact@v4\n        with:\n          name: my-artifact # NOTE: same artifact name\n          path: my-file.txt\n          overwrite: true\n```\n\n### Uploading Hidden Files\n\nBy default, hidden files are ignored by this action to avoid unintentionally uploading sensitive information.\n\nIf you need to upload hidden files, you can use the `include-hidden-files` input.\nAny files that contain sensitive information that should not be in the uploaded artifact can be excluded\nusing the `path`:\n\n```yaml\n- uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    include-hidden-files: true\n    path: |\n      path/output/\n      !path/output/.production.env\n```\n\nHidden files are defined as any file beginning with `.` or files within folders beginning with `.`.\nOn Windows, files and directories with the hidden attribute are not considered hidden files unless\nthey have the `.` prefix.\n\n## Limitations\n\n### Number of Artifacts\n\nWithin an individual job, there is a limit of 500 artifacts that can be created for that job.\n\nYou may also be limited by Artifacts if you have exceeded your shared storage quota. Storage is calculated every 6-12 hours. See [the documentation](https://docs.github.com/en/billing/managing-billing-for-github-actions/about-billing-for-github-actions#calculating-minute-and-storage-spending) for more info.\n\n### Zip archives\n\nWhen an Artifact is uploaded, all the files are assembled into an immutable Zip archive. There is currently no way to download artifacts in a format other than a Zip or to download individual artifact contents.\n\n### Permission Loss\n\nFile permissions are not maintained during artifact upload. All directories will have `755` and all files will have `644`. For example, if you make a file executable using `chmod` and then upload that file, post-download the file is no longer guaranteed to be set as an executable.\n\nIf you must preserve permissions, you can `tar` all of your files together before artifact upload. Post download, the `tar` file will maintain file permissions and case sensitivity.\n\n```yaml\n- name: 'Tar files'\n  run: tar -cvf my_files.tar /path/to/my/directory\n\n- name: 'Upload Artifact'\n  uses: actions/upload-artifact@v4\n  with:\n    name: my-artifact\n    path: my_files.tar\n```\n\n## Where does the upload go?\n\nAt the bottom of the workflow summary page, there is a dedicated section for artifacts. Here's a screenshot of something you might see:\n\n\u003cimg src=\"https://github.com/user-attachments/assets/bcb7120f-f445-4a3e-9596-77f85f7e0af0\" width=\"700\" height=\"300\"\u003e\n\n\nThere is a trashcan icon that can be used to delete the artifact. This icon will only appear for users who have write permissions to the repository.\n\nThe size of the artifact is denoted in bytes. The displayed artifact size denotes the size of the zip that `upload-artifact` creates during upload. The Digest column will display the SHA256 digest of the artifact being uploaded.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Factions%2Fupload-artifact","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Factions%2Fupload-artifact","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Factions%2Fupload-artifact/lists"}