🎉 DevOps Interview Prep Bundle is live — 1000+ Q&A across 20 topicsGet it →
All Articles

GitHub Actions Node 20 Removal: Migrate JavaScript Actions to Node 24

GitHub removed Node 20 from Actions runners on September 23, 2026. Audit workflows, update action versions, and prepare self-hosted runners for Node 24.

DevOpsBoys4 min read
Share:Tweet

GitHub removed Node 20 from GitHub Actions runners on September 23, 2026. JavaScript actions now run on Node 24, and the temporary opt-out environment variable no longer works.

This does not mean every Node.js application in a workflow must immediately use Node 24. The change affects the JavaScript runtime bundled with the Actions runner for executing JavaScript actions such as checkout, setup, caching, and third-party actions. Your application runtime is still controlled separately by tools such as actions/setup-node.

What Changed

GitHub made Node 24 the default action runtime on June 16, 2026. Teams could temporarily set ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true to keep using Node 20. On September 23, GitHub removed Node 20 from the runner, so that escape hatch is no longer available.

The practical consequences are:

  • action maintainers must publish releases whose action.yml uses runs.using: node24;
  • workflow owners must upgrade to action releases that support Node 24;
  • self-hosted runners need a current runner release and a supported host platform;
  • macOS 13.4 and earlier and ARM32 self-hosted runners are not supported by Node 24.

Inventory Every Action Before Editing

Search workflow files for local and marketplace actions:

bash
rg -n "uses:" .github/workflows .github/actions

Group the results into first-party GitHub actions, vendor actions, internal actions, and Docker or composite actions. The runtime change directly affects JavaScript actions. Composite actions may still call JavaScript actions, so inspect their steps too.

For each external action, identify the currently pinned version and the latest trusted release. Do not mechanically replace every tag with @main; immutable commit SHAs or reviewed major-version tags remain safer for production workflows.

Update Workflow Dependencies

Upgrade first-party actions to current releases that support Node 24. For example, a workflow might move from older majors to the current documented majors:

yaml
steps:
  - name: Check out repository
    uses: actions/checkout@v5
 
  - name: Configure Node.js
    uses: actions/setup-node@v5
    with:
      node-version: 22
      cache: npm

Notice that node-version: 22 can remain. setup-node itself runs with the runner's action runtime, while the configured version runs your application commands.

For third-party actions, read the release notes and action.yml from the exact version you plan to use. A major-version bump may contain input, output, permission, or behavior changes unrelated to Node 24.

Update an Internal JavaScript Action

An internal action declares its runtime in action.yml:

yaml
name: Validate deployment metadata
description: Validate the release manifest before deployment
runs:
  using: node24
  main: dist/index.js

Then update dependencies, rebuild the distributable bundle, and commit the generated dist output if your action repository follows GitHub's standard JavaScript-action pattern.

bash
npm ci
npm test
npm run build
git diff --check

Changing only runs.using is not enough when the bundled code or dependencies are incompatible with Node 24. Test the built artifact, not just the TypeScript source.

Check Self-Hosted Runner Compatibility

For self-hosted runners, record the runner version, operating system version, and CPU architecture. Node 24 is incompatible with macOS 13.4 and earlier and does not officially support ARM32.

Check a runner service log or its diagnostics page for the installed runner version. Upgrade using the documented runner update process, and replace unsupported hosts rather than attempting to restore the removed Node 20 runtime.

A safe rollout is:

  1. update one non-production runner group;
  2. run representative build, cache, artifact, security, and deployment workflows;
  3. confirm custom actions and post-job cleanup steps complete;
  4. update the remaining runner groups in controlled waves;
  5. remove the obsolete Node 20 opt-out from workflow and runner environments.

Test More Than the Happy Path

JavaScript actions can run setup, main, and post-job entry points. A workflow may appear successful until a cache save, artifact cleanup, or credential teardown step fails at the end.

Test pull requests, pushes, tags, scheduled runs, reusable workflows, and manual deployments. Also verify fork behavior and environment approvals because an action upgrade can change default permissions or inputs.

Migration Checklist

  • Inventory all uses: references and internal actions.
  • Upgrade first-party actions to Node 24-compatible releases.
  • Review third-party release notes before version changes.
  • Change internal JavaScript actions to runs.using: node24.
  • Rebuild and test committed action bundles.
  • Upgrade self-hosted runners and unsupported hosts.
  • Remove ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION.
  • Test post-job hooks and every important workflow trigger.
  • Pin third-party actions according to your supply-chain policy.

If your pipeline is already failing, use the focused GitHub Actions Node 24 runner fix to diagnose the action and host separately.

Sources

🔧

Today I Fixed

Short real fixes from production — posted daily

Browse fixes
Newsletter

Stay ahead of the curve

Get the latest DevOps, Kubernetes, AWS, and AI/ML guides delivered straight to your inbox. No spam — just practical engineering content.

Related Articles

Comments