GitHub Actions Expands Retention Policy to Encompass Checks, Runs, and Statuses
Effective October 1, 2026, GitHub Actions has significantly altered its data retention policy, bringing checks, workflow runs, and commit statuses under the same retention umbrella as artifacts and logs. This means that these previously long-lived records, which were retained for over 400 days irrespective of user settings, will now be subject to automatic cleanup based on the configured retention period. The default retention period is 90 days, and for public repositories, this remains the maximum.
This change is crucial for any organization leveraging GitHub Actions for their CI/CD pipelines. The metadata associated with checks, workflow runs, and statuses often serves as vital evidence for auditing, compliance, and post-incident analysis. For instance, a green checkmark on an old commit might be part of a release's audit trail, or a workflow run's metadata could explain the exact conditions of a production deployment. The new policy necessitates a proactive review of existing retention settings at the enterprise, organization, and repository levels. Failure to do so could result in the irreversible loss of critical historical data, potentially impacting regulatory compliance or the ability to debug past issues.
This development aligns with a broader industry trend towards more granular control over data lifecycle management in cloud-native environments, particularly within CI/CD platforms. As CI/CD pipelines become increasingly central to software delivery and security, the need for precise data governance, including retention and immutability, becomes paramount. We've seen similar efforts across other platforms to provide better control over logs and build artifacts, often driven by cost optimization, compliance requirements, and security best practices. The shift also highlights the evolving understanding of CI/CD data as a critical asset, not just ephemeral operational output.
In practice, practitioners should immediately audit their GitHub Actions retention settings. This involves identifying repositories that produce production releases or handle sensitive data and mapping any regulatory or internal compliance requirements to explicit retention periods. For any data that must be retained longer than GitHub's allowed maximums (especially the 90-day cap for public repositories), an external archiving strategy is now essential. This could involve exporting specific release evidence bundles – including commit SHAs, workflow IDs, actor information, and artifact checksums – to a dedicated, immutable archive. It's important to note that changing retention settings after the fact will not restore already deleted data, emphasizing the urgency of this review. Furthermore, teams should consider the cost implications, as longer artifact and log retention can increase billing, even though workflow metadata itself is not directly billed as storage.
Read original source