GitHub Actions Retention Policy Expands to Cover Checks, Runs, and Statuses, Demanding Immediate Audit for Compliance
Effective October 1, 2026, GitHub has expanded the scope of its Actions retention policy to include checks, workflow runs, and commit statuses, alongside the previously covered artifacts and logs. This means that these crucial elements of the CI/CD pipeline will now be automatically removed after the configured retention period. While the default retention period remains 90 days, organizations and enterprises have specific caps, and public repositories cannot retain these records beyond 90 days. This policy also applies to checks and statuses generated by third-party integrations, not just those created directly by GitHub Actions.
This change is significant because it elevates the retention setting from a mere storage cost optimization to a critical operational and compliance consideration. Previously, checks, workflow runs, and commit statuses were retained for over 400 days regardless of the artifact and log retention setting. Now, if an organization's retention policy is set to a shorter duration, vital release evidence and audit trails could be inadvertently deleted. This has direct implications for regulatory compliance, post-incident forensics, and the overall integrity of the software supply chain. For instance, a green check on an older commit might be essential release evidence, or a workflow run could provide crucial context about a production deployment.
This development fits into a broader trend of increasing scrutiny on software supply chain security and compliance. As CI/CD pipelines become more complex and integral to software delivery, the need for robust auditing and traceability grows. Recent events, such as critical vulnerabilities in CI/CD platforms and the rise of AI-driven development, have highlighted the expanded attack surface and the importance of maintaining verifiable records. The industry is moving towards more stringent requirements for provenance and immutability in software delivery, making comprehensive retention policies a necessity.
In practice, DevOps teams and compliance officers must immediately audit their current GitHub Actions retention settings at the enterprise, organization, and repository levels. It's no longer sufficient to assume that historical records will be available indefinitely. Organizations should establish clear requirements for how long checks, workflow runs, and commit statuses need to be retained based on their internal policies and regulatory obligations. For repositories requiring longer retention than the default, the settings must be explicitly adjusted. It's also critical to remember that changing the setting retroactively will not restore already deleted data. Therefore, September 2026 should be treated as a migration window to prevent data loss. Furthermore, organizations should consider external archiving solutions for highly sensitive or long-term retention needs, especially since longer artifact and log retention can increase billable storage.
Read original source