✓ No known CVEs patched in this version
Affected surfaces
Summary
AI summaryUpdates Linux arm bash, OSX x64 bash, and Linux x64 ```bash across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77‑80) Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77‑80) Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Medium |
Add new env var to allow single‑prefix multiline logs on stdout Add new env var to allow single‑prefix multiline logs on stdout Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
Propagate actions dependencies Propagate actions dependencies Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Update setup job starting logs Update setup job starting logs Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Execute debugger REPL commands inside job container Execute debugger REPL commands inside job container Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Send welcome message in debugger console on connect Send welcome message in debugger console on connect Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Dependency | Medium |
Update Docker to v29.5.0 and Buildx to v0.34.0 Update Docker to v29.5.0 and Buildx to v0.34.0 Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Medium |
Update .NET SDK to version 8.0.421 Update .NET SDK to version 8.0.421 Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fix: expand commit hash regex to support SHA‑256 (64‑char) hashes Fix: expand commit hash regex to support SHA‑256 (64‑char) hashes Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
BrokerServer should not retry on 401 responses BrokerServer should not retry on 401 responses Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Low |
Do not retry and report action download 403 errors Do not retry and report action download 403 errors Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Refactor | Low |
Move DAP setup to setup job step Move DAP setup to setup job step Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Refactor | Low |
Update snapshot-if context and functions Update snapshot-if context and functions Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump System.ServiceProcess.ServiceController from 10.0.6 to 10.0.7 by @dependabot[bot] in https://github.com/actions/runner/pull/4370
- Bump @actions/glob from 0.6.1 to 0.7.0 in /src/Misc/expressionFunc/hashFiles by @dependabot[bot] in https://github.com/actions/runner/pull/4367
- feat: propagate actions dependencies by @nodeselector in https://github.com/actions/runner/pull/4372
- Not retry and report action download 403. by @TingluoHuang in https://github.com/actions/runner/pull/4391
- Update setup job starting logs by @GitPaulo in https://github.com/actions/runner/pull/4383
- fix: expand commit hash regex to support SHA-256 (64-char) hashes by @yaananth in https://github.com/actions/runner/pull/4347
- Move dap setup to setup job step by @rentziass in https://github.com/actions/runner/pull/4403
- Add support for Ubuntu 26.04 (liblttng-ust1t64, libicu77-80) by @dvaldivia in https://github.com/actions/runner/pull/4394
- Update dotnet sdk to latest version @8.0.421 by @github-actions[bot] in https://github.com/actions/runner/pull/4428
- Update Docker to v29.5.0 and Buildx to v0.34.0 by @github-actions[bot] in https://github.com/actions/runner/pull/4425
- Execute debugger REPL commands inside job container by @rentziass in https://github.com/actions/runner/pull/4420
- Send welcome message in debugger console on connect by @rentziass in https://github.com/actions/runner/pull/4419
- Update snapshot-if context and functions by @drielenr in https://github.com/actions/runner/pull/4443
- chore: update Node versions by @github-actions[bot] in https://github.com/actions/runner/pull/4452
- Allow disable node v8 maglev jit compiler on node24. by @TingluoHuang in https://github.com/actions/runner/pull/4447
- Update Node 24 default date to June 16th, 2026 by @salmanmkc in https://github.com/actions/runner/pull/4462
- Populate telemetry for non-action post-job steps by @drielenr in https://github.com/actions/runner/pull/4463
- Add SDK types and results plumbing for background step control by @lokesh755 in https://github.com/actions/runner/pull/4472
- Add job execution view model by @rentziass in https://github.com/actions/runner/pull/4470
- Add thread-safety locks to StepsContext by @lokesh755 in https://github.com/actions/runner/pull/4475
- Add background step deferral infrastructure and metadata plumbing by @lokesh755 in https://github.com/actions/runner/pull/4479
- Wire job execution view into DAP by @rentziass in https://github.com/actions/runner/pull/4471
- Background steps execution engine by @lokesh755 in https://github.com/actions/runner/pull/4476
- Update Docker to v29.5.2 and Buildx to v0.34.1 by @github-actions[bot] in https://github.com/actions/runner/pull/4451
- BrokerServer should not retry on 401. by @TingluoHuang in https://github.com/actions/runner/pull/4445
- Add new env var to allow single-prefix multiline logs on stdout by @nuclearpidgeon in https://github.com/actions/runner/pull/4424
- Bump Microsoft.DevTunnels.Connections from 1.3.39 to 1.3.48 by @dependabot[bot] in https://github.com/actions/runner/pull/4441
- Bump System.Formats.Asn1 and System.Security.Cryptography.Pkcs by @dependabot[bot] in https://github.com/actions/runner/pull/4369
New Contributors
- @GitPaulo made their first contribution in https://github.com/actions/runner/pull/4383
- @dvaldivia made their first contribution in https://github.com/actions/runner/pull/4394
- @drielenr made their first contribution in https://github.com/actions/runner/pull/4443
- @nuclearpidgeon made their first contribution in https://github.com/actions/runner/pull/4424
Full Changelog: https://github.com/actions/runner/compare/v2.334.0...v2.335.0
Note: Actions Runner follows a progressive release policy, so the latest release might not be available to your enterprise, organization, or repository yet.
To confirm which version of the Actions Runner you should expect, please view the download instructions for your enterprise, organization, or repository.
See https://docs.github.com/en/enterprise-cloud@latest/actions/hosting-your-own-runners/adding-self-hosted-runners
Windows x64
We recommend configuring the runner in a root folder of the Windows drive (e.g. "C:\actions-runner"). This will help avoid issues related to service identity folder permissions and long file path restrictions on Windows.
The following snipped needs to be run on powershell:
# Create a folder under the drive root
mkdir \actions-runner ; cd \actions-runner
# Download the latest runner package
Invoke-WebRequest -Uri https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-win-x64-2.335.1.zip -OutFile actions-runner-win-x64-2.335.1.zip
# Extract the installer
Add-Type -AssemblyName System.IO.Compression.FileSystem ;
[System.IO.Compression.ZipFile]::ExtractToDirectory("$PWD\actions-runner-win-x64-2.335.1.zip", "$PWD")
Windows arm64
We recommend configuring the runner in a root folder of the Windows drive (e.g. "C:\actions-runner"). This will help avoid issues related to service identity folder permissions and long file path restrictions on Windows.
The following snipped needs to be run on powershell:
# Create a folder under the drive root
mkdir \actions-runner ; cd \actions-runner
# Download the latest runner package
Invoke-WebRequest -Uri https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-win-arm64-2.335.1.zip -OutFile actions-runner-win-arm64-2.335.1.zip
# Extract the installer
Add-Type -AssemblyName System.IO.Compression.FileSystem ;
[System.IO.Compression.ZipFile]::ExtractToDirectory("$PWD\actions-runner-win-arm64-2.335.1.zip", "$PWD")
OSX x64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-osx-x64-2.335.1.tar.gz
# Extract the installer
tar xzf ./actions-runner-osx-x64-2.335.1.tar.gz
OSX arm64 (Apple silicon)
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-osx-arm64-2.335.1.tar.gz
# Extract the installer
tar xzf ./actions-runner-osx-arm64-2.335.1.tar.gz
Linux x64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-linux-x64-2.335.1.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-x64-2.335.1.tar.gz
Linux arm64
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-linux-arm64-2.335.1.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-arm64-2.335.1.tar.gz
Linux arm
# Create a folder
mkdir actions-runner && cd actions-runner
# Download the latest runner package
curl -O -L https://github.com/actions/runner/releases/download/v2.335.1/actions-runner-linux-arm-2.335.1.tar.gz
# Extract the installer
tar xzf ./actions-runner-linux-arm-2.335.1.tar.gz
Using your self hosted runner
For additional details about configuring, running, or shutting down the runner please check out our product docs.
SHA-256 Checksums
The SHA-256 checksums for the packages included in this build are shown below:
- actions-runner-win-x64-2.335.1.zip eb65c95277af42bcf3778a799c41359d224ba2a67b4de26b7cea1729b09c803d
- actions-runner-win-arm64-2.335.1.zip 6cd1409daad8be4f77deb0c677ceb6153fccbab2e33af4fdc1b3465bd42ec742
- actions-runner-osx-x64-2.335.1.tar.gz b2fe57b2ae5b0bc1605f9fc0723c07eedf06167321d3478ce0440f15e5b0a010
- actions-runner-osx-arm64-2.335.1.tar.gz e1a9bc7a3661e06fa0b129d15c2064fe65dc81a431001d8958a9db1409b73769
- actions-runner-linux-x64-2.335.1.tar.gz 4ef2f25285f0ae4477f1fe1e346db76d2f3ebf03824e2ddd1973a2819bf6c8cf
- actions-runner-linux-arm64-2.335.1.tar.gz 6d1e85bfd1a506a8b17c1f1b9b57dba458ffed90898799aaa9f599520b0d9207
- actions-runner-linux-arm-2.335.1.tar.gz d9810476ceebb6739913ed16afd5c61664e53312a444ee5226e9010a4219a864
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]