GitHub Actions removals · checked

set-env and add-path disabled since 16 Nov 2020: the fix

set-env and add-path workflow commands: disabled 16 Nov 2020, 2153 days ago. A step that prints ::set-env or ::add-path fails, unless ACTIONS_ALLOW_UNSECURE_COMMANDS is set to true, which reopens the injection hole the commands were removed for (CVE-2020-15228). The fix: Write echo "NAME=value" >> "$GITHUB_ENV" and echo "/some/dir" >> "$GITHUB_PATH". Check your workflows now, with nothing to install: grep -rnE "::(set-env|add-path)" .github

$ grep -rnE "::(set-env|add-path)" .github

Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds each name as written in your workflow files; a value set in another file and passed in (a matrix from JSON, a reusable workflow's input) needs a look of its own. The fix is in the first paragraph above. The dates come from this data.

The facts

What
set-env and add-path workflow commands
Matches
Steps that print ::set-env, ::add-path
Effect
Breaks a job
Announced
1 October 2020
Deprecated from
1 October 2020
In effect since
16 Nov 2020disabled 16 Nov 2020, 2153 days ago
After the date
A step that prints ::set-env or ::add-path fails, unless ACTIONS_ALLOW_UNSECURE_COMMANDS is set to true, which reopens the injection hole the commands were removed for (CVE-2020-15228).
The fix
Write echo "NAME=value" >> "$GITHUB_ENV" and echo "/some/dir" >> "$GITHUB_PATH".

Sources

An email before each brownout, for the repos you watch, is not built.

It would re-read your workflows every day and email you a week and a day before each brownout or removal that would hit them, with no change to your repo. agentcheck's free hourly watch covers MCP servers only today. If you would pay for this one, say so with one click. The click is counted; nothing else is sent or stored.

Other GitHub Actions removals

Every removal, by date

actions-eol is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Dates come from GitHub's own pages, read on the day shown; github.com only, since GitHub Enterprise Server keeps its own schedule.