✓ No known CVEs patched in this version
Affected surfaces
Summary
AI summaryUpdates Linux arm bash, OSX x64 bash, and Linux x64 ```bash across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77‑80) Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77‑80) Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Update Docker to v29.5.2 and Buildx to v0.34.1 Update Docker to v29.5.2 and Buildx to v0.34.1 Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Update dotnet SDK to version 8.0.421 Update dotnet SDK to version 8.0.421 Source: llm_adapter@2026-06-08 Confidence: low |
— |
| Feature | Low |
Add new env var to allow single‑prefix multiline logs on stdout Add new env var to allow single‑prefix multiline logs on stdout Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Low |
Propagate actions dependencies Propagate actions dependencies Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Execute debugger REPL commands inside job container Execute debugger REPL commands inside job container Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Send welcome message in debugger console on connect Send welcome message in debugger console on connect Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Populate telemetry for non-action post‑job steps Populate telemetry for non-action post‑job steps Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Add background step deferral infrastructure and metadata plumbing Add background step deferral infrastructure and metadata plumbing Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
Implement background steps execution engine Implement background steps execution engine Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Dependency | Low |
Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Dependency | Low |
Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Dependency | Low |
Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Dependency | Low |
Bump Microsoft.DevTunnels.Connections from 1.3.39 to 1.3.48 Bump Microsoft.DevTunnels.Connections from 1.3.39 to 1.3.48 Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Bugfix | Medium |
Not retry and report action download 403 errors Not retry and report action download 403 errors Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Bugfix | Medium |
Fix: expand commit hash regex to support SHA‑256 (64‑char) hashes Fix: expand commit hash regex to support SHA‑256 (64‑char) hashes Source: llm_adapter@2026-06-08 Confidence: low |
— |
| Bugfix | Low |
BrokerServer should not retry on 401 errors BrokerServer should not retry on 401 errors Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Move DAP setup to setup job step Move DAP setup to setup job step Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Update snapshot-if context and functions Update snapshot-if context and functions Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Add SDK types and results plumbing for background step control Add SDK types and results plumbing for background step control Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Add job execution view model Add job execution view model Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Add thread‑safety locks to StepsContext Add thread‑safety locks to StepsContext Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Refactor | Low |
Wire job execution view into DAP Wire job execution view into DAP Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 by @dependabot[bot] in https://github.com/actions/runner/pull/4370
- Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles by @dependabot[bot] in https://github.com/actions/runner/pull/4367
- feat: propagate actions dependencies by @nodeselector in https://github.com/actions/runner/pull/4372
- Not retry and report action download 403. by @TingluoHuang in https://github.com/actions/runner/pull/4391
- Update setup job starting logs by @GitPaulo in https://github.com/actions/runner/pull/4383
- fix: expand commit hash regex to support SHA-256 (64-char) hashes by @yaananth in https://github.com/actions/runner/pull/4347
- Move dap setup to setup job step by @rentziass in https://github.com/actions/runner/pull/4403
- Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77-80) by @dvaldivia in https://github.com/actions/runner/pull/4394
- Update dotnet sdk to latest version @8.0.421 by @github-actions[bot] in https://github.com/actions/runner/pull/4428
- Update Docker to v29.5.0 and Buildx to v0.34.0 by @github-actions[bot] in https://github.com/actions/runner/pull/4425
- Execute debugger REPL commands inside job container by @rentziass in https://github.com/actions/runner/pull/4420
- Send welcome message in debugger console on connect by @rentziass in https://github.com/actions/runner/pull/4419
- Update snapshot-if context and functions by @drielenr in https://github.com/actions/runner/pull/4443
- chore: update Node versions by @github-actions[bot] in https://github.com/actions/runner/pull/4452
- Allow disable node v8 maglev jit compiler on node24. by @TingluoHuang in https://github.com/actions/runner/pull/4447
- Update Node 24 default date to June 16th, 2026 by @salmanmkc in https://github.com/actions/runner/pull/4462
- Populate telemetry for non-action post-job steps by @drielenr in https://github.com/actions/runner/pull/4463
- Add SDK types and results plumbing for background step control by @lokesh755 in https://github.com/actions/runner/pull/4472
- Add job execution view model by @rentziass in https://github.com/actions/runner/pull/4470
- Add thread-safety locks to StepsContext by @lokesh755 in https://github.com/actions/runner/pull/4475
- Add background step deferral infrastructure and metadata plumbing by @lokesh755 in https://github.com/actions/runner/pull/4479
- Wire job execution view into DAP by @rentziass in https://github.com/actions/runner/pull/4471
- Background steps execution engine by @lokesh755 in https://github.com/actions/runner/pull/4476
- Update Docker to v29.5.2 and Buildx to v0.34.1 by @github-actions[bot] in https://github.com/actions/runner/pull/4451
- BrokerServer should not retry on 401. by @TingluoHuang in https://github.com/actions/runner/pull/4445
- Add new env var to allow single-prefix multiline logs on stdout by @nuclearpidgeon in https://github.com/actions/runner/pull/4424
- Bump Microsoft.DevTunnels.Connections from 1.3.39 to 1.3.48 by @dependabot[bot] in https://github.com/actions/runner/pull/4441
- Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs by @dependabot[bot] in https://github.com/actions/runner/pull/4369
New Contributors
- @GitPaulo made their first contribution in https://github.com/actions/runner/pull/4383
- @dvaldivia made their first contribution in https://github.com/actions/runner/pull/4394
- @drielenr made their first contribution in https://github.com/actions/runner/pull/4443
- @nuclearpidgeon made their first contribution in https://github.com/actions/runner/pull/4424
Full Changelog: https://github.com/actions/runner/compare/v2.334.0...v2.335.0
Note: Actions Runner follows a progressive release policy, so the latest release might not be available to your enterprise, organization, or repository yet.
To confirm which version of the Actions Runner you should expect, please view the download instructions for your enterprise, organization, or repository.
See https://docs.github.com/en/enterprise-cloud@latest/actions/hosting-your-own-runners/adding-self-hosted-runners
Windows x64
We recommend configuring the runner in a root folder of the Windows drive (e.g. "C:\actions-runner"). This will help avoid issues related to service identity folder permissions and long file path restrictions on Windows.
The following snipped needs to be run on powershell:
# Create a folder under the drive root
mkdir \actions-runner ; cd \actions-runner
# Download the latest runner package
Invoke-WebRequest -Uri https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-win-x64-2.335.0.zip -OutFile actions-runner-win-x64-2.335.0.zip
# Extract the installer
Add-Type -AssemblyName System.IO.Compression.FileSystem ;
[System.IO.Compression.ZipFile]::ExtractToDirectory("$PWD\actions-runner-win-x64-2.335.0.zip", "$PWD")
Windows arm64
We recommend configuring the runner in a root folder of the Windows drive (e.g. "C:\actions-runner"). This will help avoid issues related to service identity folder permissions and long file path restrictions on Windows.
The following snipped needs to be run on powershell:
# Create a folder under the drive root
mkdir \actions-runner ; cd \actions-runner
# Download the latest runner package
Invoke-WebRequest -Uri https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-win-arm64-2.335.0.zip -OutFile actions-runner-win-arm64-2.335.0.zip
# Extract the installer
Add-Type -AssemblyName System.IO.Compression.FileSystem ;
[System.IO.Compression.ZipFile]::ExtractToDirectory("$PWD\actions-runner-win-arm64-2.335.0.zip", "$PWD")
OSX x64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-osx-x64-2.335.0.tar.gz
# Extract the installer
tar xzf ./actions-runner-osx-x64-2.335.0.tar.gz
OSX arm64 (Apple silicon)
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-osx-arm64-2.335.0.tar.gz
# Extract the installer
tar xzf ./actions-runner-osx-arm64-2.335.0.tar.gz
Linux x64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-linux-x64-2.335.0.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-x64-2.335.0.tar.gz
Linux arm64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-linux-arm64-2.335.0.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-arm64-2.335.0.tar.gz
Linux arm
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.0/actions-runner-linux-arm-2.335.0.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-arm-2.335.0.tar.gz
Using your self hosted runner
For additional details about configuring, running, or shutting down the runner please check out our product docs.
SHA-256 Checksums
The SHA-256 checksums for the packages included in this build are shown below:
- actions-runner-win-x64-2.335.0.zip 0422df90994cc5e2350238fb2707029fddaa156e7e4562b14e35086f94417e87
- actions-runner-win-arm64-2.335.0.zip e0f4601ec0822c6a453672e65f6f58c2285b7390376ce00ce001021e15918c98
- actions-runner-osx-x64-2.335.0.tar.gz c3537857b03fe008fd2fc6f7e9dc12aa9692c32b00c672e425684ca79fed4716
- actions-runner-osx-arm64-2.335.0.tar.gz a1b382dda2cbb00a5e78fc21e7dbf4dbcf35edf44d6fd8686c8302e6f15cd065
- actions-runner-linux-x64-2.335.0.tar.gz cf484ecd77f8832103cbf6f6dc4f930cfe93a71cd37895ebda0165fec1fa920b
- actions-runner-linux-arm64-2.335.0.tar.gz 454b6ff207b90d35a39580ae37854fd68839d0f9af9c5e73b51d7d0842ae2b1c
- actions-runner-linux-arm-2.335.0.tar.gz 854acd84462ea009f29712d980318af0422151fe5b9fa3b39defd87b3d55b352
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]