GitHub Actions removals · checked
set-env and add-path disabled since 16 Nov 2020: the fix
set-env and add-path workflow commands: disabled 16 Nov 2020, 2153 days ago. A step that prints ::set-env or ::add-path fails, unless ACTIONS_ALLOW_UNSECURE_COMMANDS is set to true, which reopens the injection hole the commands were removed for (CVE-2020-15228). The fix: Write echo "NAME=value" >> "$GITHUB_ENV" and echo "/some/dir" >> "$GITHUB_PATH". Check your workflows now, with nothing to install: grep -rnE "::(set-env|add-path)" .github
$ grep -rnE "::(set-env|add-path)" .github
Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds each name as written in your workflow files; a value set in another file and passed in (a matrix from JSON, a reusable workflow's input) needs a look of its own. The fix is in the first paragraph above. The dates come from this data.
The facts
- What
- set-env and add-path workflow commands
- Matches
- Steps that print
::set-env,::add-path - Effect
- Breaks a job
- Announced
- 1 October 2020
- Deprecated from
- 1 October 2020
- In effect since
- 16 Nov 2020disabled 16 Nov 2020, 2153 days ago
- After the date
- A step that prints ::set-env or ::add-path fails, unless ACTIONS_ALLOW_UNSECURE_COMMANDS is set to true, which reopens the injection hole the commands were removed for (CVE-2020-15228).
- The fix
- Write echo "NAME=value" >> "$GITHUB_ENV" and echo "/some/dir" >> "$GITHUB_PATH".
Sources
An email before each brownout, for the repos you watch, is not built.
It would re-read your workflows every day and email you a week and a day before each brownout or removal that would hit them, with no change to your repo. agentcheck's free hourly watch covers MCP servers only today. If you would pay for this one, say so with one click. The click is counted; nothing else is sent or stored.
Counted. Thank you; nothing else was sent.Other GitHub Actions removals
- upload-artifact and download-artifact v1 to v3 · stopped working 30 Jan 2025, 617 days ago
- actions/cache v1 and v2, and pins below v3.4.0 or v4.2.0 · stopped working 1 Mar 2025, 587 days ago
- macOS 10.15 runner image · removed 1 Dec 2022, 1408 days ago
- macOS 12 runner image · removed 3 Dec 2024, 675 days ago
- macOS 13 runner image · removed 4 Dec 2025, 309 days ago
- Ubuntu 18.04 runner image · removed 3 Apr 2023, 1285 days ago
- Ubuntu 20.04 runner image · removed 15 Apr 2025, 542 days ago
- Windows Server 2019 runner image · removed 30 Jun 2025, 466 days ago
actions-eol is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Dates come from GitHub's own pages, read on the day shown; github.com only, since GitHub Enterprise Server keeps its own schedule.