Skip to content

runs-on

v3.1.2 Feature

This release adds 12 notable features for engineering teams evaluating rollout.

Published 1mo Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

aws ci-cd cloudformation ec2-spot github-runners on-premise
+2 more
self-hosted self-hosted-runners

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Spotlight canonicalizes GitHub App IDs, extends runner preinstall timeouts to 30 min, adds a Windows GPU image, and includes stack name in job details; CloudFormation disables SSH by default, scopes Lambda log groups, tightens IAM permissions, and upgrades Python runtimes; Terraform similarly disables SSH for security groups, scopes logs, broadens IAM restrictions, and enables DynamoDB point‑in‑time recovery.

Full changelog

Spotlight

  • Flex now canonicalizes workflow job GitHub App installation IDs from the current app registry, preventing stale installation IDs from breaking token refresh and active job processing.
  • Pool runners now allow preinstall scripts to run for up to 30 minutes, while non-pool lifecycle scripts keep the existing 10-minute timeout.
  • Added the windows25-gpu-x64 default image definition for Windows GPU runners.
  • Runner job details now include the RunsOn stack name, making multi-stack diagnostics easier.

CloudFormation

  • SSH access is disabled by default for new CloudFormation installs, and the managed networking template no longer opens SSH from 0.0.0.0/0 unless explicitly configured.
  • Lambda log groups now use stack-scoped /runs-on/<stack>/lambda/... names with explicit log-write policies.
  • Tightened CloudFormation IAM permissions for Lambda invocation, EC2 runner launches, S3 cache access, ECR Public access, CloudWatch metrics, SSM license state, WAF sync, and cleanup operations.
  • Upgraded Python Lambda runtimes to python3.14 and hardened launch-template XML parsing.

Terraform

  • SSH access is disabled by default for new Flex and Fleet module security groups.
  • Terraform control-plane Lambda log groups now use stack-scoped names with explicit log-write policies.
  • Tightened Terraform IAM permissions for runner launches, Lambda/API Gateway invocation, ECR Public reads, S3 cache prefixes, CloudWatch metrics, SSM license state, WAF sync, SQS, DynamoDB indexes, EFS, and cleanup operations.
  • Enabled point-in-time recovery for the Flex workflow jobs DynamoDB table.

Other fixes

  • Sanitized agent runtime EC2 tag keys and values before applying them to instances.

Release resources

  • Upgrade guide: https://runs-on.com/guides/upgrade/
  • CloudFormation template: https://runs-on.s3.eu-west-1.amazonaws.com/cloudformation/template-v3.1.2.yaml

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track runs-on

Get notified when new releases ship.

Sign up free

About runs-on

Self-hosted GitHub Actions runners made simple. For AWS. 10x cheaper, 40% faster, and unlimited caching. Best alternative to Actions Runner Controller.

All releases →

Related context

Beta — feedback welcome: [email protected]