GitHub Actions removals · checked

pull_request_target blocked by default from 2 Nov 2026 in public repos

pull_request_target in public repositories: blocked by default 2 Nov 2026, in 24 days. In a public repository with no Actions event policy, workflows triggered by pull_request_target stop running: GitHub's default workflow execution protection blocks the event. Private and internal repositories are exempt. The rule has run in evaluate mode since 17 Sep 2026, so its Insights show what it would block. The fix: If the workflow needs pull_request_target, allow it in an Actions event policy for the repository or organisation (or allowlist that workflow file); otherwise trigger it on pull_request. Check your workflows now, with nothing to install: grep -rn "pull_request_target" .github/workflows

$ grep -rn "pull_request_target" .github/workflows

Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds each name as written in your workflow files; a value set in another file and passed in (a matrix from JSON, a reusable workflow's input) needs a look of its own. The fix is in the first paragraph above. The dates come from this data.

The facts

What
pull_request_target in public repositories
Matches
Workflows triggered by pull_request_target in public repositories
Effect
Breaks a job
Announced
17 September 2026
Date
2 Nov 2026blocked by default 2 Nov 2026, in 24 days
After the date
In a public repository with no Actions event policy, workflows triggered by pull_request_target stop running: GitHub's default workflow execution protection blocks the event. Private and internal repositories are exempt. The rule has run in evaluate mode since 17 Sep 2026, so its Insights show what it would block.
The fix
If the workflow needs pull_request_target, allow it in an Actions event policy for the repository or organisation (or allowlist that workflow file); otherwise trigger it on pull_request.

Notes

  • A scan of local files cannot tell whether the repository is public or already has an event policy; a scan of owner/repo knows whether it is public.

Sources

An email before each brownout, for the repos you watch, is not built.

It would re-read your workflows every day and email you a week and a day before each brownout or removal that would hit them, with no change to your repo. agentcheck's free hourly watch covers MCP servers only today. If you would pay for this one, say so with one click. The click is counted; nothing else is sent or stored.

Other GitHub Actions removals

Every removal, by date

actions-eol is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Dates come from GitHub's own pages, read on the day shown; github.com only, since GitHub Enterprise Server keeps its own schedule.