Lesson 3 / 25

Runners

Hosted or self-hosted machines.

Where jobs execute

GitHub-hosted runners are fresh virtual machines (Ubuntu, Windows, macOS, plus larger and ARM options) created for each job and discarded afterwards; usage is billed by the minute for private repositories beyond the free allowance, with macOS and larger runners costing more. Self-hosted runners run on your own machines for special hardware, network access or cost reasons, but you must secure and maintain them; never use self-hosted runners for public repositories, where anyone can open a pull request that runs code on them.

Choosing a runner

Labels select the machine type.

runs-on: ubuntu-latest        GitHub-hosted Linux (most common, cheapest)
runs-on: windows-latest       GitHub-hosted Windows
runs-on: macos-latest         GitHub-hosted macOS (higher per-minute cost)
runs-on: [self-hosted, linux, gpu]   your own machine with matching labels

Prefer hosted runners for untrusted code

Fresh, isolated VMs limit what a malicious pull request can reach.

Quick check: Why are self-hosted runners risky for public repositories?

  • They do not support YAML
  • They are slower
  • They cannot run Linux
  • Anyone can open a pull request that runs code on your machine
Answer

Anyone can open a pull request that runs code on your machine — Untrusted code needs disposable runners.