Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

RunsOn cache diagnostics

This GitHub Action prints the decoded GitHub Actions runtime-token claims and the repository IDs in the workflow event. RunsOn support uses the report to diagnose cache isolation across GitHub hosts.

Usage

Add this step near the start of the affected job:

- name: Inspect cache runtime token
  uses: runs-on/debug-cache@v1

The action needs no checkout, permissions, secrets, or inputs. Copy the entire RunsOn cache token diagnostics log group and send it privately to RunsOn support.

Data disclosure

The report contains:

  • the decoded, signed JWT header and claims;
  • repository and owner IDs from the workflow event;
  • selected GitHub and runner context;
  • a SHA-256 fingerprint of the token.

The report never contains the raw runtime token or its signature. It cannot be used as a bearer credential. Decoded claims can still contain private repository, workflow, branch, and internal identifiers. Review the report and send it only through a private support channel.

The action does not call GitHub, AWS, RunsOn, or any cache endpoint. It does not write an artifact or persist the token.

Development

Requires Node.js 24 or newer:

npm test

License

MIT

About

Safely inspect GitHub Actions runtime-token claims for RunsOn cache diagnostics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages