The DAP transport is a secret-carrying channel that bypasses the job
log's masking, so every user-visible string a DAP producer relays is run
through the runner's SecretMasker at the point of construction. That
behavior was correct but unpinned: nothing failed if a sink lost its
mask call.
Add L0 regression tests covering each previously untested sink:
DapReplExecutor stdout, stderr, the EvaluateResponseBody error path,
and expression expansion
DapDebugger the HandleMessageAsync catch-all error response,
the threads response job label, and the stopped
event step description
Each test was verified to fail when its mask call is removed.
The one REPL sink deliberately left unmasked is the console echo of the
script the user just typed, which only reflects their own input back to
the session that sent it. Cover its truncation behavior instead, so the
gap reads as a decision rather than an oversight.
DapReplExecutorL0 gains a FakeStepHost so the output pipeline can be
exercised without launching a process, replaying canned stdout/stderr
through the same events a real process raises.
Refs github/actions-runtime#5586 (security review finding #13).
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e4fd6981-5088-4e99-9cc2-d1b16bf3c44a
GitHub Actions Runner
The runner is the application that runs a job from a GitHub Actions workflow. It is used by GitHub Actions in the hosted virtual environments, or you can self-host the runner in your own environment.
Get Started
For more information about installing and using self-hosted runners, see Adding self-hosted runners and Using self-hosted runners in a workflow
Runner releases:
Note
Thank you for your interest in this GitHub repo, however, right now we are not taking contributions.
We continue to focus our resources on strategic areas that help our customers be successful while making developers' lives easier. While GitHub Actions remains a key part of this vision, we are allocating resources towards other areas of Actions and are not taking contributions to this repository at this time. The GitHub public roadmap is the best place to follow along for any updates on features we’re working on and what stage they’re in.
We are taking the following steps to better direct requests related to GitHub Actions, including:
-
We will be directing questions and support requests to our Community Discussions area
-
High Priority bugs can be reported through Community Discussions or you can report these to our support team https://support.github.com/contact/bug-report.
-
Security Issues should be handled as per our SECURITY.md
We will still provide security updates for this project and fix major breaking changes during this time.
You are welcome to still raise bugs in this repo.



