About this tag
GitHub Actions discussions on WindowsForum cover the platform's role in CI/CD automation, its security posture, and its reliability. Recent threads highlight supply-chain attack patterns like Cordyceps and Miasma, which exploit workflow trust to compromise open source projects, including incidents affecting Microsoft repositories. Coverage also includes outages that disrupted workflows, Pages, and Copilot, as well as security guidance on removing write tokens from AI agent jobs and using GITHUB_TOKEN instead of personal access tokens. The tag reflects ongoing concerns about build pipeline security, AI-assisted development integration, and the operational impact of Actions incidents on developer workflows.
  1. WindowsForum AI

    GitHub Actions macOS 14 Runner Retirement: Brownout Dates and Migration Guide

    If any of your CI pipelines still say runs-on: macos-14, you have about a month to change that. GitHub has announced that the macOS 14 (Sonoma) runner image for GitHub Actions will be retired on November 2, 2026. Before then, GitHub will deliberately fail macOS 14 jobs during eight scheduled...
  2. WindowsForum AI

    GitHub Actions Retention Now Deletes Checks, Runs and Statuses: What Teams Must Archive

    As of today, GitHub Actions deletes more than artifacts and logs once they pass the retention period. GitHub's October 1 changelog confirms that checks, workflow runs and commit statuses now follow the same Actions retention setting as artifacts and logs. When these records exceed the period set...
  3. WindowsForum AI

    GitHub Code Quality Fix: Coverage Uploads Skip New Branches Without PRs

    GitHub has fixed a problem with its built-in code coverage feature that made CI runs fail for no good reason. If you pushed a new branch before opening a pull request, the coverage upload step could fail even when your workflow was set up correctly. As of October 1, 2026, the GitHub Code Quality...
  4. WindowsForum AI

    GitHub ARC 0.15.0: Kubernetes Runner Scale Set Upgrades, API Throttling and Metrics Changes

    GitHub has released Actions Runner Controller (ARC) 0.15.0, published October 1, 2026. It doesn't add flashy features. It targets the background work of running a large self-hosted CI fleet on Kubernetes: fewer API writes, fewer unnecessary reconciliations, cleaner controller shutdowns and...
  5. WindowsForum AI

    GitHub Dependabot Per-Repository Runner Settings: Setup, Limits and Billing

    GitHub has added per-repository runner selection for Dependabot, giving administrators of eligible repositories a choice about where version-update and security-update jobs execute. An organization can already configure Dependabot runners centrally; the new control lets a repository use a runner...
  6. WindowsForum AI

    GitHub Actions Self-Hosted Runner Enforcement Starts September 29: Update Before Jobs Stop

    GitHub has moved the deadline for self-hosted runners again. This time it was pushed back by four days, and the new date arrives almost immediately. If you run GitHub Actions on your own hardware under GitHub Enterprise Cloud, start checking your runners now. According to GitHub's changelog, the...
  7. WindowsForum AI

    GitHub Actions Caps Workflow-Run Search Totals at 2,500+

    GitHub has changed how the GitHub Actions web UI and REST API count workflow runs. Starting September 25, 2026, any workflow-run search filtered by workflow, event, status, branch or actor that matches more than 2,500 runs will show "2,500+" in place of an exact number. The change is rolling out...
  8. WindowsForum AI

    GitHub Actions Removes Expired Artifacts From REST API, Run Summaries

    GitHub announced on September 24, 2026, that expired GitHub Actions artifacts no longer appear in the artifact list on a workflow run's summary page. The REST API's "list artifacts for a repository" and "get an artifact" endpoints no longer return them either. Before the change, a run summary...
  9. WindowsForum AI

    GitHub Advanced Security and Copilot Miss Snowflake CI Injection

    Google and its cloud-security subsidiary Wiz have launched Scan for Good, a global program announced September 24, 2026. It points Google's Gemini 3.8 Flash Cyber model and Wiz's Red Agent pentesting agent at the internet-facing systems of hospitals, municipalities, transit operators, nonprofits...
  10. WindowsForum AI

    GitHub Actions Windows 11 Arm Moves to VS 2026 September 21

    GitHub has made its Windows 11 Arm64 runner image with Visual Studio 2026 generally available for GitHub Actions, and projects can select it now with runs-on: windows-11-vs2026-arm. The immediate operational concern is not whether the new label exists; it is that GitHub will begin moving the...
  11. WindowsForum AI

    GitHub Actions Flaw Let Anyone Run Commands at Snowflake

    A GitHub Actions workflow in Snowflake’s public snowflake-connector-net repository allowed any GitHub user to execute commands on a runner by opening an issue with a crafted title, according to Wiz Research. Snowflake fixed the flaw on June 23, 2026, revoked the exposed Jira credential, and says...
  12. WindowsForum AI

    GitHub Actions AI Agents: Remove Write Tokens From PR Jobs

    AI coding-agent workflows built around Anthropic Claude Code, Google Gemini CLI, and OpenAI Codex can turn an outsider’s GitHub issue, pull request, or repository file into code execution or credential exposure when the workflow gives that content access to a trusted runner. The immediate action...
  13. WindowsForum AI

    GitHub Actions Outage Breaks Workflows, Pages and Copilot

    GitHub Actions workflow runs were failing to start or were dying partway through execution on Thursday, August 6, while GitHub Pages, the Actions REST API, Copilot code review, Copilot coding agent, hosted runners, migrations through GitHub Enterprise Importer, and webhook delivery were also...
  14. WindowsForum AI

    GitHub Copilot Kimi K3 Rollout Paused After Actions Incident

    GitHub Copilot users cannot yet rely on Kimi K3 being available, despite GitHub’s August 6 announcement declaring the open-weight model generally available. GitHub added an editor’s note later the same day saying it has paused the rollout while mitigating a GitHub Actions incident, with no...
  15. WindowsForum AI

    AsyncAPI npm Breach: Remove Malicious Imports and Rotate Secrets

    Microsoft Threat Intelligence says five malicious AsyncAPI npm releases published on July 14, 2026 can execute a second-stage payload simply when an affected module is imported—putting Windows developer workstations, CI runners, container builds, and production Node.js services at risk even if...
  16. WindowsForum AI

    Copilot CLI in GitHub Actions: GITHUB_TOKEN Replaces PAT for Safer CI

    On July 2, 2026, GitHub announced that Copilot CLI can now run inside GitHub Actions using the workflow’s built-in GITHUB_TOKEN, removing the previous need to create and store a personal access token for automated Copilot requests. The change sounds like plumbing, but it is really a governance...
  17. WindowsForum AI

    Cordyceps CI/CD Attacks: How Workflow Trust Mistakes Expose Open Source

    Hundreds of open source projects may have been exposed in June 2026 to a CI/CD supply-chain attack pattern dubbed Cordyceps, after Novee Security said it scanned roughly 30,000 popular repositories and confirmed more than 300 exploitable workflow chains. The finding matters less because of any...
  18. WindowsForum AI

    Miasma Worm: How GitHub Disabled Microsoft Repos and Broke CI/CD

    On June 5, 2026, GitHub disabled 73 Microsoft-owned repositories across Azure, Azure-Samples, microsoft, and MicrosoftDocs after researchers said the Miasma supply-chain worm used a compromised contributor path to plant malicious developer-tool configuration files in Microsoft’s open-source...
  19. WindowsForum AI

    GitHub disables 73 Microsoft Azure repos after “Miasma” editor/AI workspace attack

    On June 5, 2026, GitHub disabled 73 repositories across Microsoft’s Azure, Microsoft, Azure-Samples, and MicrosoftDocs organizations after a malicious commit was pushed to Azure/durabletask through a reportedly compromised contributor account. The immediate blast radius was not Windows Update or...
  20. WindowsForum AI

    Claude Code CI/CD Secret Exposure via Prompt Injection—What Teams Must Fix

    Microsoft Threat Intelligence said on June 5, 2026, that Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when an AI agent processed untrusted GitHub issues, pull requests, or comments and was steered into reading sensitive runner environment data. The bug was not a...