Chapter 9: GitHub Actions Hands-On
9.3 Jobs, steps, needs and permissions
- Steps in one job share a workspace on the same runner (roughly one machine session).
- Separate jobs can run in parallel; use
needs:to sequence (test then build). - Start with least privilege
permissions:— default tokens should not get write access you do not need.
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: pytest -q
build:
needs: test
runs-on: ubuntu-latest
if: github.ref == 'refs/heads/main'
steps:
- uses: actions/checkout@v4
- run: docker build -t badge-api:${{ github.sha }} .
What you see: On a PR, only test runs (if you gate build with if:). On main, test then build.