→ Back to Home
GitHub Actions

GitHub Actions Bolsters Supply Chain Security with Enhanced Retention and Runner Controls

GitHub Actions has rolled out several key updates that directly address the security and operational efficiency of CI/CD pipelines. Most notably, the retention policy for checks, workflow runs, and statuses has been unified with that of artifacts and logs, defaulting to 90 days. Previously, these records were retained for over 400 days, regardless of the configured artifact retention. This change, effective October 1, 2026, means that historical CI/CD data, including critical audit trails and release evidence, will now be subject to the same retention limits. Additionally, GitHub has introduced a new REST API for runner version deprecations, allowing users to programmatically determine when registration and runtime support for specific runner versions will end. Finally, reusable workflows gain four new job context properties, providing more granular information about their source identity at runtime. This matters significantly to anyone managing GitHub Actions workflows, especially those operating in regulated environments or with strict compliance requirements. The unified retention policy means that teams must actively review and adjust their retention settings at the enterprise, organization, and repository levels to prevent the premature deletion of essential historical data. Failure to do so could lead to gaps in audit trails and loss of valuable operational insights. The new runner deprecation API is a boon for proactive maintenance, enabling administrators to plan runner upgrades well in advance of deprecation, thereby minimizing disruptions to build and deployment processes. For developers utilizing reusable workflows, the expanded job context properties offer enhanced traceability and debugging capabilities, which are vital for complex, interconnected CI/CD architectures. These updates align with a broader industry trend towards strengthening software supply chain security and improving the governance of automated workflows. As CI/CD pipelines become increasingly central to software delivery, they also become prime targets for attackers. Recent incidents have highlighted vulnerabilities in dependency management, secret handling, and the execution of untrusted code within CI/CD environments. GitHub's response, through features like workflow-level dependency locking, scoped secrets, and native egress firewalls (as outlined in their 2026 security roadmap), demonstrates a clear commitment to making Actions more secure by default. The current changes, particularly around data retention, are a foundational step in ensuring that organizations have better control and visibility over their entire CI/CD footprint. In practice, practitioners should immediately audit their GitHub Actions retention settings across all repositories, organizations, and enterprises. It is crucial to identify any workflows that generate data required for long-term retention (e.g., for compliance, post-mortems, or historical analysis) and adjust the settings accordingly. For data that needs to be retained beyond GitHub's maximum limits, a robust external archiving strategy should be implemented and tested. Furthermore, DevOps teams should integrate the new runner deprecation API into their operational tooling to automate the monitoring and planning of runner updates. Finally, developers building reusable workflows should explore how the new job context properties can be leveraged to improve the robustness and debuggability of their shared automation. The key takeaway is proactive management: these changes are not merely cosmetic but require concrete action to maintain security, compliance, and operational continuity.
#github actions#ci/cd#security#data retention#runner management#supply chain security
Read original source