Actions
We track 21 posts about Actions from 17 engineering blogs. Most active: SitePoint, Ariya Hidayat, Docker. Latest post: Oct 1, 2026.
Companies writing about Actions
Recent posts
Node 20 GitHub Actions Deprecated: How to Migrate Workflows (opens on the source site)
With Node 20 GitHub Actions deprecated, workflows need updating. Learn how to separate runner runtimes from project Node versions, update custom action metadata, and audit native module dependencies. Continue reading Node 20 GitHub Actions Deprecated: How to Migrate Workflows on SitePoint.
Terraform 1.16 completes Actions lifecycles and brings imports into child modules (opens on the source site)
Managing infrastructure rarely ends when a resource is created. Teams may need to take a final backup, deregister an asset, or clean up an external system before infrastructure disappears. And when adopting existing infrastructure into Terraform, reusable modules have not been able to carry their own import logic: the root module had to own it. HashiCorp Terraform 1.16 addresses both gaps. Terraform Actions can now run before and after resource destruction, and declarative `import` blocks can now live inside child modules. Together, these improvements keep more operational and adoption intent…
Automating DevSecOps Static Analysis with GitHub Actions and Agent Skills (opens on the source site)
Implement an automated CI DevSecOps static security analysis workflow in GitHub Actions using sandboxed Agent Skills that outputs standard SARIF reports for native GitHub Code Scanning integration. Continue reading Automating DevSecOps Static Analysis with GitHub Actions and Agent Skills on SitePoint.
Push images to Vercel Container Registry from GitHub Actions (opens on the source site)
Vercel ·
You can now push container images from GitHub Actions to Vercel Container Registry (VCR) without storing long-lived registry credentials. The new vercel/vcr-action/login action authenticates your workflow using GitHub OIDC. It exchanges the workflow’s OIDC token for a short-lived Vercel access token, then uses that token to log in to vcr.vercel.com. When the job ends, the action logs out and revokes the Vercel token. To start: Create an OIDC policy on your Vercel team that matches the GitHub repository and workflow, and grants read-write access to VCR. Store your Vercel team ID as a GitHub…
Optimizing GitHub Actions for Agent PRs: Speculative Test Slicing and AST Impact Analysis (opens on the source site)
Fix CI saturation from high-frequency agent pull requests with AST change-impact analysis and speculative test slicing in GitHub Actions. Continue reading Optimizing GitHub Actions for Agent PRs: Speculative Test Slicing and AST Impact Analysis on SitePoint.
GitHub Actions leaking secrets when Miri output is cached (opens on the source site)
Rust ·
The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches. While not necessary a vulnerability in and of itself, when paired with GitHub Actions caching behavior, it is possible for this to expose secrets to PRs. Overview GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing cache poisoning). Rust projects tend to speed up CI by caching binaries built by cargo install and…
Securing AI Pull Requests: Building a Deterministic AST Audit Harness in GitHub Actions (opens on the source site)
Build a deterministic CI/CD audit harness that checks AI coding-agent pull requests for AST prototype pollution, secret leakage, and unsafe egress before merge. Continue reading Securing AI Pull Requests: Building a Deterministic AST Audit Harness in GitHub Actions on SitePoint.
Test GitHub Actions Locally with Act (opens on the source site)
GitHub Actions are a great way to implement CI/CD into your projects, whether personal or professional. GitHub has a lot of great tools to help with CI/CD, but GitHub Actions in particular is very helpful. However, writing actions can be tedious and a little annoying, especially if you don’t know what you’re doing. On top […] The post Test GitHub Actions Locally with Act appeared first on Atomic Spin.
Important Update for GitHub Actions OIDC: Immutable Subject Claims (opens on the source site)
GitHub has introduced Immutable Subject Claims for OIDC (OpenID Connect) in GitHub Actions. This update fixes a security issue where the subject claim in the OIDC token used to be based on organisation and repository names instead of permanent identifiers. What was the problem? Organisation and repository names can be changed or reused. This means that if an organisation or repository is deleted or renamed, another actor could, in theory, create a new repository or organisation with the same name. This would let them land in the same namespace within the subject claim, and in the worst case…
Running AI agents in GitHub Actions with Docker Sandboxes (opens on the source site)
Docker ·
Run AI agents in GitHub Actions with Docker Sandboxes. See how isolated agents can run Testcontainers tests, fix code, and open draft pull requests.
17,600 Actions: Agent Security Is a Systems Problem (opens on the source site)
Docker ·
The OpenAI/Hugging Face incident exposed a new challenge for AI agent security. 17,600 attacker actions show why AI agent security can’t rely on human review. Explore the controls needed to constrain, observe, and govern agents at speed.
Fast Haskell Scripts on GitHub Actions (opens on the source site)
Magix is a neat tool that lets us run Haskell programs as scripts1. We put a shebang on top mentioning Magix, list the Haskell packages we need, and ./script.hs just works. This post is about running such a script fast(er) on GitHub Actions.
How To Publish To NPM From GitHub Actions (opens on the source site)
Using The New NPM OIDC Trusted Publishing Workflow At the end of 2025, NPM registry revoked all personal NPM tokens that I used to publish new NPM package releases. This change improves the security of the entire NPM publishing workflow, but has disrupted my CI process. For example, the new feature of cypress-timestamps has not been released, failing with the error "SemanticReleaseError: Invalid npm token.". Hmm, what do we do now? We could use publish to NPM using local npm CLI commands, entering the 2FA token, etc. But I really hate this idea. I have more than 400 NPM packages, so the…
Best GitHub Actions Alternatives in 2026 (opens on the source site)
GitHub Actions became the default CI/CD choice for millions of repositories simply because it’s built into GitHub. But “default” and “best” are not the same thing — and in 2026, the gap between the two has gotten harder to ignore. A ten-hour outage in July, a supply-chain attack that backdoored over 5,500 repositories in May, […] The post Best GitHub Actions Alternatives in 2026 appeared first on Semaphore.
Automatically Signing a Windows EXE with Azure Trusted Signing, dotnet sign, and GitHub Actions (opens on the source site)
Mac Tahoe (in Beta as of the time of this writing) has this new feature called Edge Light that basically puts a bright picture of an Edge Light around your screen and basically uses the power of OLED to give you a virtual ring light. So I was like, why can't we also have nice things? I wrote (vibed, with GitHub Copilot and Claude Sonnet 4.5) a Windows Edge Light App (source code at https://github.com/shanselman/WindowsEdgeLight and you can get the latest release here https://github.com/shanselman/WindowsEdgeLight/releases or the app will check for new releases and autoupdate with Updatum).…
Pinning GitHub Actions (opens on the source site)
If you’re using GitHub Actions in your projects, you should be pinning your actions to specific commit SHAs instead of using tags or branches.
Server Actions with Toast (useEffect) (opens on the source site)
Learn how to display toast notifications from React Server Actions in React (and Next.js) with useEffect and useActionState ...
Decreasing CI Build times up to 50% by caching derived data using github actions. (opens on the source site)
We had a problem. Our CI pipeline was increasingly becoming a bottleneck in our iOS continuous integration. We here at Kogan like to develop at a fast pace, however we were constantly being held up waiting for builds to complete, leading to a lot of frustration within the team. The rest of the engineering team had switched to using Github Actions(GHA), and with us still using CircleCI, it was time for us to make the change. This was the perfect time for us to re-evaluate how our pipeline was working, to ensure it was the most efficient that it can be. With a build time of over 30 minutes…
Automatic npm publishing, with GitHub Actions & npm granular tokens (opens on the source site)
This week, at long last, GitHub announced granular access tokens for npm. This is a big deal! It's great for security generally, but also particularly useful if you maintain any npm packages, as it removes the main downside of automating npm publishing, by allowing you to give CI jobs only a very limited token instead of full 2FA-free access to your account. In the past, I've wished for this, because I maintain a fair few npm packages including some very widely used ones. The previous solution of "just disable 2FA on your account, create an all-powerful access token with global access to…
Continuous Integration for React Native Apps with GitHub Actions (opens on the source site)
For React Native mobile apps targeting Android and iOS, an easy way to setup its continuous integration is to take advantage of Actions, an automation workflow service provided by GitHub. Even better, for open-source projects, GitHub Action offers unlimited free running minutes (at the time of this writing).
On GitHub Actions with MSYS2 (opens on the source site)
Thanks to the complete GitHub Actions for MSYS2, it is easier than ever to construct a continuous integration setup for building with compilers and toolchains which can run on MSYS2.
Related topics
This page is generated automatically from the engineering blogs we follow. Every post links to its source, where it was published. See all sources.