GitHub posted the last notice on September 23, 2026: Node 20 is gone from GitHub Actions runners, and JavaScript actions run on Node 24. The temporary opt-out, ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION, stopped working with it. GitHub first announced the deprecation on September 19, 2025, so maintainers had a year. This week the grace period ended for github.com and GitHub with Data Residency.
What moved
The change concerns the runtime the runner uses to execute JavaScript actions, the ones whose action.yml declares runs.using. Composite actions and Docker actions don't declare a Node runtime there. Your own build steps choose their Node version through whatever setup step you run, and the changelog doesn't mention those.
| Item | Status |
|---|---|
| Runtime for JavaScript actions | Node 24 |
| ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION | no longer available |
| Self-hosted runner on macOS 13.4 or earlier | unsupported |
| Self-hosted runner on ARM32 | unsupported |
| First-party actions | newest versions use Node 24 |
The last two rows hit teams with hardware in a closet. Node 24 won't run on macOS 13.4 and earlier, and it has no official ARM32 support. A Mac mini that stopped at Ventura or a 32-bit Raspberry Pi registered as a runner falls off the supported list.
If you maintain an action
GitHub asks maintainers to change runs.using to node24 and publish a new release "as soon as possible." The metadata change takes one line:
# action.yml
runs:
- using: node20
+ using: node24
main: dist/index.js
The line is the easy part. Rebuild dist/ with Node 24 in your own CI, run the action's tests on it, and cut a new major or minor tag so that users on @v3 or @v3.2 pick it up.
If you use actions
Your workflows run third-party JavaScript actions on Node 24 now, whatever their action.yml says. An action that breaks on Node 24 fails at run time with a stack trace from inside the action, and that trace reads like a bug in your workflow.
Start with an inventory of what you pin:
# all action references in this repo, most used first
grep -rhoE "uses: [^ ]+@[^ ]+" .github/workflows | sort | uniq -c | sort -rn
# local JavaScript actions that still declare node20
grep -rnE "using: *['\"]?node20" --include=action.yml --include=action.yaml .
Then bump each action to its newest release. The first-party ones under actions/ have Node 24 releases already. For third-party actions, check the repository for a release that mentions Node 24, and read the issues if the last release is old.
Delete the opt-out while you're there. It does nothing now, and leaving it in a workflow tells the next reader that Node 20 still runs:
env:
- ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true
CI: true
Self-hosted runners
GitHub's statement covers self-hosted runners on the two platforms Node 24 can't serve. You have two choices for those machines. Upgrade macOS past 13.4, or move the jobs to a 64-bit host. Running them unsupported until something breaks trades a planned migration for an outage on a day you didn't pick.
For the rest of your fleet, keep the runner application current, since the runner ships the Node runtime it uses for actions.
This week
Sep 19, 2025
GitHub announces the Node 20 deprecation for Actions runners.Sep 23, 2026
Node 20 removed. The opt-out stops working.
- Run the two grep commands above in each repository with workflows.
- Bump each action to a release that targets Node 24, starting with the ones in deploy workflows.
- Remove
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSIONfrom workflow and repository variables. - Retire or upgrade self-hosted runners on macOS 13.4 or older and on ARM32.
- If you publish an action, change
runs.using, rebuild on Node 24 and release.
If a workflow goes red this week with an error from inside a third-party action, check that action's releases for Node 24 support before you debug your own YAML.
Volodymyr Chornous

