GitHub Actions
- Pronunciation
- GIT-hub AK-shunz
In short
GitHub Actions is GitHub's built-in automation platform: YAML workflows in a repo run tests, builds and deployments on events like a push or pull request.
What is GitHub Actions?
GitHub Actions became generally available in 2019 and turned GitHub into a CI/CD platform. Workflows are YAML files stored in the repository under .github/workflows. Each workflow says when it should run, for example on every push, on pull requests, on a schedule or by hand, and what it should do.
A workflow contains jobs, and each job runs on a runner, a fresh virtual machine with Linux, Windows or macOS that GitHub provides, or a self-hosted machine. A job is a list of steps: shell commands such as npm test, or reusable actions such as actions/checkout to fetch the code. Jobs run in parallel unless one depends on another, and a matrix can run the same job across several versions or operating systems.
Thousands of ready-made actions in the GitHub Marketplace handle common tasks: setting up a language, caching dependencies, publishing packages, deploying to cloud providers or commenting on pull requests. Secrets such as API keys are stored encrypted in the repository settings and passed to the steps that need them.
A common misconception is that GitHub Actions is only for CI. It can automate almost anything triggered by repository events: labeling issues, releasing versions, updating dependencies or publishing documentation. Because third-party actions run with access to your code and secrets, pinning them to a specific version is an important security practice.
At a glance
Key takeaways
- GitHub Actions runs automated workflows inside GitHub.
- Workflows are YAML files in .github/workflows, triggered by events.
- Jobs run on GitHub-hosted or self-hosted runners, step by step.
- Marketplace actions handle common tasks like checkout, caching and deploys.
- Pin third-party actions to versions, since they can see your code and secrets.
Example
# .github/workflows/ci.yml
name: CI
on: [push, pull_request]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm testReaders ask
Is GitHub Actions free?
It is free for public repositories on GitHub-hosted runners. Private repositories get a monthly allowance of free minutes, and usage beyond that is billed.
What is a GitHub Actions runner?
The machine that executes a job. GitHub provides hosted runners with Linux, Windows or macOS, and you can also register your own machines as self-hosted runners.
What is the difference between a workflow, a job and a step?
A workflow is the whole automation in one YAML file. It contains jobs, which run on separate runners, and each job is a sequence of steps that run commands or actions.
See also
- CI/CDDevOps & Cloud, p. 9CI/CD is a set of automated practices that build, test, and release code changes frequently, so software can be delivered to users quickly and safely.
- GitHubVersion Control, p. 25GitHub is a platform for hosting Git repositories and working on code together, with pull requests, code review, issues and the largest open-source community.
- DevOpsDevOps & Cloud, p. 14DevOps is a set of practices and a culture that brings software development and IT operations together to deliver software faster and more reliably.
- YAMLDevOps & Cloud, p. 54YAML is a human-readable data format that uses indentation instead of brackets, widely used for configuration files in DevOps tools and CI/CD pipelines.
- GitVersion Control, p. 10Git is a free, open-source distributed version control system that tracks changes to files over time, so developers can collaborate and undo mistakes.
- Secrets ManagementSecurity, p. 37Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
Sources
Spotted a mistake or something missing on this page?Suggest an edit