CI/CD
Implement continuous integration and delivery pipelines. Discover tools and best practices for automating builds, tests, and deployments.
Posts
GitHub Actions Removed Node 20. Find Every node20 Action You Still Run
Since September 23, GitHub Actions runs every node20 action on Node 24, and the opt-out is gone. An action that still works only adds a warning, so they are easy to miss until one breaks. Here is how to list every action your workflows use, read its runs.using value, and catch the ones hidden behind SHA pins and composite actions.
GitHub Started Enforcing Self-Hosted Runner Versions. We Tested What Happens
GitHub started enforcing self-hosted runner versions on September 29. We tried four runner versions against a free github.com organization and asked GitHub's own API about every release. One was refused, one connected and then exited while its job waited in the queue, and the API scheduled every version's end about nine weeks after its successor.
CI Passed 6 of 6 Migrations. A Neon Branch of Production Passed 1
How to test Postgres migrations before production: branch production on Neon in seconds, run each migration while an app keeps reading and writing, and gate on errors, failed queries, lock stalls and lost rows. The six migrations that passed on our fixture database failed five times on the branch.
Your Trace Dies the Moment the Pipeline Shells Out
OpenTelemetry has a Release Candidate spec for passing trace context through environment variables, which is how you connect a CI run to the build tool it spawns. Two runnable demos: one showing four orphaned traces becoming one, and one showing why BAGGAGE across a trust boundary is the part worth arguing about.
The 9 Types of API Testing, and Where Each Belongs in Your Pipeline
Telling load testing from stress testing is easy. What shapes delivery is which of the nine run on every pull request, and which only run after a deploy.
What Does One Merge Actually Cost You in CI?
Wall-clock time and machine minutes are different numbers, and most teams track only one. Here is how to get both from your own repo.
Explaining CI Failures Automatically with a GitHub Action
We built a GitHub Action that reads a failing job log and tells you what broke, using DigitalOcean serverless inference. The interesting part was not the model call. It was throwing away 92% of the log before sending it.
One git push to RCE: the anatomy of CVE-2026-3854 and the parsing bug behind it
A single git push could execute code on GitHub's backend, with cross-tenant reach on github.com itself. The root cause is a bug you almost certainly have somewhere too: untrusted input smuggled through a delimited internal header.
The pwn request just got harder: what actions/checkout v7 changes, and what it does not
GitHub is backporting a fork-checkout block to actions/checkout, with enforcement on July 20, 2026. Here is what a pwn request actually is, what the change stops, and the three ways your pipeline is still exposed after you upgrade.
How to Implement Progressive Delivery with Feature Flags
Learn how to implement progressive delivery using feature flags, canary releases, and gradual rollouts to ship changes safely in production without risking your entire user base.
The GitHub Actions Workflow That Eliminated Our DevOps Bottleneck
How we reduced deployment time from 2 hours to 8 minutes using smart GitHub Actions patterns and parallel execution strategies.