#GitHub Actions
Loot, blog posts and adjacent themes connected to this topic. Follow the tag to keep it in your orbit.
More from this topic
Related reads
Update GitHub Actions OIDC Trust Policies Before New Repos Break Cloud Deploys
GitHub now enforces immutable OIDC subject claims for new repositories and post-July 15 renames or transfers. Teams using GitHub Actions to …
GitHub actions/checkout v7: Security and Breaking Changes
GitHub actions/checkout v7 blocks common pwn-request patterns. See the July 16 backport, affected workflows, breaking behavior and upgrade c…
Run Copilot CLI in Actions without storing a PAT
GitHub Copilot CLI can now run in GitHub Actions with the built-in GITHUB_TOKEN, cutting long-lived PAT secrets out of organization-owned au…
Audit GitHub Actions self-hosted runners before the July brownouts
GitHub Actions will start brownouts for outdated self-hosted runners before full enforcement begins for GitHub Enterprise Cloud with Data Re…
Stop cache poisoning in GitHub Actions with read-only untrusted triggers
GitHub Actions now gives read-only cache tokens to low-trust default-branch workflow triggers, reducing cache-poisoning paths from pull_requ…
Run GitHub Actions steps in parallel without losing separate logs
GitHub Actions now supports parallel steps with background, wait, wait-all, cancel, and parallel syntax. It is useful for faster CI jobs, bu…


