GitHub Actions removals · checked

CodeQL Action v3 deprecated in December 2026: move to v4

CodeQL Action v3: deprecated Dec 2026, in 53+ days (GitHub gives only the month). GitHub stops updating CodeQL Action v3; new CodeQL analysis capabilities come only to v4. GitHub has not said that v3 stops running. v3 runs on Node 20, so it is already forced onto Node 24. The fix: Change github/codeql-action/init, analyze, autobuild and upload-sarif from @v3 to @v4. Code scanning's default setup moves by itself. Check your workflows now, with nothing to install: grep -rnE "github/codeql-action(/[a-z-]+)?@v?(3)\b" .github

$ grep -rnE "github/codeql-action(/[a-z-]+)?@v?(3)\b" .github

Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds each name as written in your workflow files; a value set in another file and passed in (a matrix from JSON, a reusable workflow's input) needs a look of its own. The fix is in the first paragraph above. The dates come from this data.

The facts

What
CodeQL Action v3
Matches
github/codeql-action v3
Effect
Warns; the job still runs
Announced
28 October 2025
Date
Dec 2026deprecated Dec 2026, in 53+ days (GitHub gives only the month)
After the date
GitHub stops updating CodeQL Action v3; new CodeQL analysis capabilities come only to v4. GitHub has not said that v3 stops running. v3 runs on Node 20, so it is already forced onto Node 24.
The fix
Change github/codeql-action/init, analyze, autobuild and upload-sarif from @v3 to @v4. Code scanning's default setup moves by itself.
Replace
github/codeql-action → github/codeql-action@v4

Notes

  • GitHub gives the month, not the day: v3 is deprecated together with GHES 3.19.

Sources

An email before each brownout, for the repos you watch, is not built.

It would re-read your workflows every day and email you a week and a day before each brownout or removal that would hit them, with no change to your repo. agentcheck's free hourly watch covers MCP servers only today. If you would pay for this one, say so with one click. The click is counted; nothing else is sent or stored.

Other GitHub Actions removals

Every removal, by date

actions-eol is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Dates come from GitHub's own pages, read on the day shown; github.com only, since GitHub Enterprise Server keeps its own schedule.