The post-merge Docker publish workflow (CI-CD build and deploy docker images based on the last commit in the target branch) has been failing on every push to main since Jul 11.
This is a CI-config bug, not a code bug — all test/build merge-queue gates are green.
Symptom
The build step fails instantly with:
ERROR: failed to build: invalid tag ":": invalid reference format
The step env dump shows the cause:
DOCKER_PUBLISH_CONDITION: --tag :
i.e. it expands to --tag : with an empty repo and empty version, which buildx rejects.
Root cause
.github/workflows/ci-cd-main-branch-docker-images.yml:113:
env:
BUILD_VERSION: "${{ ... }}" # line 111
BUILD_VERSION_LATEST: "${{ ... }}" # line 112
DOCKER_PUBLISH_CONDITION: ${{ steps.def_docker_vars.outputs.keep_images > 0 && format(--tag {0}:{1} , env.DOCKER_URL, env.BUILD_VERSION) || }} # line 113
DOCKER_URL: ${{ env.DOCKERHUB_REPOSITORY }} # line 114
DOCKER_PUBLISH_CONDITION references env.DOCKER_URL and env.BUILD_VERSION, but both are siblings in the same step-level env: block. GitHub Actions evaluates every entry in an env: map against the environment as it existed before the block, so siblings cannot see each other — both resolve to empty and format(--tag {0}:{1} , , ) produces --tag :.
The --tag "$DOCKER_URL:$BUILD_VERSION_LATEST" (main-latest) tag on line 133 is fine — it is shell-expanded at runtime. Only the templated DOCKER_PUBLISH_CONDITION is broken.
Line 152 (BUILD_VERSION_CONDITION) has the identical sibling-reference mistake, but it only feeds an echo, so it is non-fatal.
Regression source
Commit 67a39dac82 — PR #22386 ("ci: fix zizmor template-injection in remaining QA/CD workflows"). It moved this expression out of the run: script (where the env context correctly includes step-level vars) into the env: block (where it does not).
Failing on every commit since:
2026-07-13 b887c6b95 failure
2026-07-13 b4ed135a4 failure
...
2026-07-12 4540ef19c failure <- first after the regression
Suggested fix
Do not reference sibling env vars — resolve from the source contexts directly (DOCKERHUB_REPOSITORY is job/workflow-level, not a sibling, so it is safe):
DOCKER_PUBLISH_CONDITION: ${{ steps.def_docker_vars.outputs.keep_images > 0 && format(--tag {0}:{1}-{2} , env.DOCKERHUB_REPOSITORY, steps.def_docker_vars.outputs.tag_name, steps.getCommitId.outputs.short_commit_id) || }}
Apply the same fix to BUILD_VERSION_CONDITION (line 152).
The post-merge Docker publish workflow (
CI-CD build and deploy docker images based on the last commit in the target branch) has been failing on every push tomainsince Jul 11.This is a CI-config bug, not a code bug — all test/build merge-queue gates are green.
Symptom
The build step fails instantly with:
The step env dump shows the cause:
i.e. it expands to
--tag :with an empty repo and empty version, which buildx rejects.Root cause
.github/workflows/ci-cd-main-branch-docker-images.yml:113:DOCKER_PUBLISH_CONDITIONreferencesenv.DOCKER_URLandenv.BUILD_VERSION, but both are siblings in the same step-levelenv:block. GitHub Actions evaluates every entry in anenv:map against the environment as it existed before the block, so siblings cannot see each other — both resolve to empty andformat(--tag {0}:{1} , , )produces--tag :.The
--tag "$DOCKER_URL:$BUILD_VERSION_LATEST"(main-latest) tag on line 133 is fine — it is shell-expanded at runtime. Only the templatedDOCKER_PUBLISH_CONDITIONis broken.Line 152 (
BUILD_VERSION_CONDITION) has the identical sibling-reference mistake, but it only feeds anecho, so it is non-fatal.Regression source
Commit
67a39dac82— PR #22386 ("ci: fix zizmor template-injection in remaining QA/CD workflows"). It moved this expression out of therun:script (where theenvcontext correctly includes step-level vars) into theenv:block (where it does not).Failing on every commit since:
Suggested fix
Do not reference sibling env vars — resolve from the source contexts directly (
DOCKERHUB_REPOSITORYis job/workflow-level, not a sibling, so it is safe):Apply the same fix to
BUILD_VERSION_CONDITION(line 152).