Skip to main content

CI/CD

Implement continuous integration and delivery pipelines. Discover tools and best practices for automating builds, tests, and deployments.

11posts

Posts

CI/CD
|12 min read

GitHub Actions Removed Node 20. Find Every node20 Action You Still Run

Since September 23, GitHub Actions runs every node20 action on Node 24, and the opt-out is gone. An action that still works only adds a warning, so they are easy to miss until one breaks. Here is how to list every action your workflows use, read its runs.using value, and catch the ones hidden behind SHA pins and composite actions.

CI/CD
|14 min read

GitHub Started Enforcing Self-Hosted Runner Versions. We Tested What Happens

GitHub started enforcing self-hosted runner versions on September 29. We tried four runner versions against a free github.com organization and asked GitHub's own API about every release. One was refused, one connected and then exited while its job waited in the queue, and the API scheduled every version's end about nine weeks after its successor.

CI/CD
|17 min read

CI Passed 6 of 6 Migrations. A Neon Branch of Production Passed 1

How to test Postgres migrations before production: branch production on Neon in seconds, run each migration while an app keeps reading and writing, and gate on errors, failed queries, lock stalls and lost rows. The six migrations that passed on our fixture database failed five times on the branch.

CI/CD
|12 min read

Your Trace Dies the Moment the Pipeline Shells Out

OpenTelemetry has a Release Candidate spec for passing trace context through environment variables, which is how you connect a CI run to the build tool it spawns. Two runnable demos: one showing four orphaned traces becoming one, and one showing why BAGGAGE across a trust boundary is the part worth arguing about.

CI/CD
|15 min read

The 9 Types of API Testing, and Where Each Belongs in Your Pipeline

Telling load testing from stress testing is easy. What shapes delivery is which of the nine run on every pull request, and which only run after a deploy.

CI/CD
|13 min read

What Does One Merge Actually Cost You in CI?

Wall-clock time and machine minutes are different numbers, and most teams track only one. Here is how to get both from your own repo.

CI/CD
|11 min read

Explaining CI Failures Automatically with a GitHub Action

We built a GitHub Action that reads a failing job log and tells you what broke, using DigitalOcean serverless inference. The interesting part was not the model call. It was throwing away 92% of the log before sending it.

CI/CD
|11 min read

One git push to RCE: the anatomy of CVE-2026-3854 and the parsing bug behind it

A single git push could execute code on GitHub's backend, with cross-tenant reach on github.com itself. The root cause is a bug you almost certainly have somewhere too: untrusted input smuggled through a delimited internal header.

CI/CD
|11 min read

The pwn request just got harder: what actions/checkout v7 changes, and what it does not

GitHub is backporting a fork-checkout block to actions/checkout, with enforcement on July 20, 2026. Here is what a pwn request actually is, what the change stops, and the three ways your pipeline is still exposed after you upgrade.

CI/CD
|10 min read

How to Implement Progressive Delivery with Feature Flags

Learn how to implement progressive delivery using feature flags, canary releases, and gradual rollouts to ship changes safely in production without risking your entire user base.

CI/CD
|7 min read

The GitHub Actions Workflow That Eliminated Our DevOps Bottleneck

How we reduced deployment time from 2 hours to 8 minutes using smart GitHub Actions patterns and parallel execution strategies.