GitHub Actions removals · checked
pull_request_target blocked by default from 2 Nov 2026 in public repos
pull_request_target in public repositories: blocked by default 2 Nov 2026, in 24 days. In a public repository with no Actions event policy, workflows triggered by pull_request_target stop running: GitHub's default workflow execution protection blocks the event. Private and internal repositories are exempt. The rule has run in evaluate mode since 17 Sep 2026, so its Insights show what it would block. The fix: If the workflow needs pull_request_target, allow it in an Actions event policy for the repository or organisation (or allowlist that workflow file); otherwise trigger it on pull_request. Check your workflows now, with nothing to install: grep -rn "pull_request_target" .github/workflows
$ grep -rn "pull_request_target" .github/workflows
Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds each name as written in your workflow files; a value set in another file and passed in (a matrix from JSON, a reusable workflow's input) needs a look of its own. The fix is in the first paragraph above. The dates come from this data.
The facts
- What
- pull_request_target in public repositories
- Matches
- Workflows triggered by
pull_request_targetin public repositories - Effect
- Breaks a job
- Announced
- 17 September 2026
- Date
- 2 Nov 2026blocked by default 2 Nov 2026, in 24 days
- After the date
- In a public repository with no Actions event policy, workflows triggered by pull_request_target stop running: GitHub's default workflow execution protection blocks the event. Private and internal repositories are exempt. The rule has run in evaluate mode since 17 Sep 2026, so its Insights show what it would block.
- The fix
- If the workflow needs pull_request_target, allow it in an Actions event policy for the repository or organisation (or allowlist that workflow file); otherwise trigger it on pull_request.
Notes
- A scan of local files cannot tell whether the repository is public or already has an event policy; a scan of owner/repo knows whether it is public.
Sources
An email before each brownout, for the repos you watch, is not built.
It would re-read your workflows every day and email you a week and a day before each brownout or removal that would hit them, with no change to your repo. agentcheck's free hourly watch covers MCP servers only today. If you would pay for this one, say so with one click. The click is counted; nothing else is sent or stored.
Counted. Thank you; nothing else was sent.Other GitHub Actions removals
- upload-artifact and download-artifact v1 to v3 · stopped working 30 Jan 2025, 617 days ago
- actions/cache v1 and v2, and pins below v3.4.0 or v4.2.0 · stopped working 1 Mar 2025, 587 days ago
- macOS 10.15 runner image · removed 1 Dec 2022, 1408 days ago
- macOS 12 runner image · removed 3 Dec 2024, 675 days ago
- macOS 13 runner image · removed 4 Dec 2025, 309 days ago
- set-env and add-path workflow commands · disabled 16 Nov 2020, 2153 days ago
- Ubuntu 18.04 runner image · removed 3 Apr 2023, 1285 days ago
- Ubuntu 20.04 runner image · removed 15 Apr 2025, 542 days ago
actions-eol is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Dates come from GitHub's own pages, read on the day shown; github.com only, since GitHub Enterprise Server keeps its own schedule.