→ Back to Home
GitHub Actions

GitHub Actions Retention Policy Expands to Cover Checks, Runs, and Statuses, Streamlining Data Management

GitHub has announced a significant update to its Actions data retention policy, effective October 1, 2026. This change brings checks, workflow runs, and statuses under the same retention umbrella that previously only covered artifacts and logs. This means that all these elements will now be automatically cleaned up once they exceed the configured retention period for a repository, organization, or enterprise. The default retention period remains 90 days, and existing caps for public repositories (90 days maximum) still apply. The UI label for this setting has been updated to "Check, workflow run, status, artifact and log retention" to reflect its broader scope. Importantly, this change is not retroactive; adjusting settings will not restore previously removed data. This development is particularly significant for practitioners managing complex CI/CD environments. Historically, checks, workflow runs, and statuses would persist for over 400 days, irrespective of shorter retention periods set for artifacts and logs. This discrepancy could lead to an accumulation of stale data, making it harder to manage storage, ensure compliance, and potentially impacting performance. By unifying the retention policy, GitHub is addressing a long-standing point of friction, offering a more coherent and manageable approach to data lifecycle within Actions. This impacts anyone using GitHub Actions, from individual developers to large enterprises, particularly those in regulated industries where data retention is a critical concern. This move aligns with a broader industry trend towards more granular control and automated governance of data within CI/CD pipelines. As software supply chains become increasingly complex and subject to stringent security and compliance requirements, platforms are evolving to provide better tools for managing the vast amounts of data generated. The ability to consistently apply retention policies across all aspects of a workflow run, including its metadata, is a step towards a more mature and auditable DevOps ecosystem. This also echoes the ongoing emphasis on "secure by default" and "verifiable automation" that GitHub has been pushing in its 2026 security roadmap for Actions, where data governance plays a crucial role in reducing the attack surface and improving overall supply chain security. In practice, practitioners should immediately review their GitHub Actions retention settings at all levels (repository, organization, and enterprise) to ensure they align with their operational needs and compliance obligations. If a longer retention period is required for checks, workflow runs, or statuses, the settings should be adjusted accordingly, keeping in mind that this will also extend the retention for artifacts and logs, potentially impacting billable storage. Conversely, organizations that previously relied on the longer implicit retention for checks and statuses for auditing purposes may now need to implement explicit archiving strategies for critical evidence that must persist beyond the configured GitHub Actions retention period. This could involve exporting specific workflow run data to external, long-term storage solutions to meet regulatory or internal audit requirements. Failure to do so could result in the loss of valuable historical data.
#github actions#data retention#ci/cd#devops#compliance#workflow management
Read original source