On the REST API fallback, a ref given without a SHA (a branch or tag of
another repository, or the default branch) left the commit output empty: the
archive was downloaded by ref and nothing recorded which commit that was.
downloadRepository now resolves the ref to its commit first
(GET /repos/{owner}/{repo}/commits/{ref} with the sha media type), downloads
that commit, and returns its SHA, which getSource sets as the output. The
downloaded content and the reported SHA are the same commit even if the ref
moves meanwhile. If the ref cannot be resolved, the download falls back to
the ref as before, a warning is logged, and the output stays empty.
When Git is not available on the runner, getSource() downloads the
repository using the REST API and returns early, before the commit
output is set. The ref output is still set by main.ts after getSource()
returns, so the step reports a ref but an empty commit, even though
action.yml documents commit unconditionally.
Set the output from the resolved settings on that path. The REST API
fallback does not create a local Git repository, so git log -1 cannot be
used there.