Lesson 3 / 25
Runners
Hosted or self-hosted machines.
Where jobs execute
GitHub-hosted runners are fresh virtual machines (Ubuntu, Windows, macOS, plus larger and ARM options) created for each job and discarded afterwards; usage is billed by the minute for private repositories beyond the free allowance, with macOS and larger runners costing more. Self-hosted runners run on your own machines for special hardware, network access or cost reasons, but you must secure and maintain them; never use self-hosted runners for public repositories, where anyone can open a pull request that runs code on them.
Choosing a runner
Labels select the machine type.
runs-on: ubuntu-latest GitHub-hosted Linux (most common, cheapest)
runs-on: windows-latest GitHub-hosted Windows
runs-on: macos-latest GitHub-hosted macOS (higher per-minute cost)
runs-on: [self-hosted, linux, gpu] your own machine with matching labelsPrefer hosted runners for untrusted code
Fresh, isolated VMs limit what a malicious pull request can reach.
Quick check: Why are self-hosted runners risky for public repositories?
- They do not support YAML
- They are slower
- They cannot run Linux
- Anyone can open a pull request that runs code on your machine
Answer
Anyone can open a pull request that runs code on your machine — Untrusted code needs disposable runners.