# Runners — GitHub Actions

Source: https://www.skillbyai.com/en/github-actions/i-runners

> Hosted or self-hosted machines.

## Where jobs execute

**GitHub-hosted runners** are fresh virtual machines (Ubuntu, Windows, macOS, plus larger and ARM options) created for each job and discarded afterwards; usage is billed by the minute for private repositories beyond the free allowance, with macOS and larger runners costing more. **Self-hosted runners** run on your own machines for special hardware, network access or cost reasons, but you must secure and maintain them; never use self-hosted runners for public repositories, where anyone can open a pull request that runs code on them.

## Choosing a runner

Labels select the machine type.

```text
runs-on: ubuntu-latest        GitHub-hosted Linux (most common, cheapest)
runs-on: windows-latest       GitHub-hosted Windows
runs-on: macos-latest         GitHub-hosted macOS (higher per-minute cost)
runs-on: [self-hosted, linux, gpu]   your own machine with matching labels
```

## Prefer hosted runners for untrusted code

Fresh, isolated VMs limit what a malicious pull request can reach.

**Quiz:** Why are self-hosted runners risky for public repositories?

- [ ] They do not support YAML
- [ ] They are slower
- [ ] They cannot run Linux
- [x] Anyone can open a pull request that runs code on your machine

*Answer:* Anyone can open a pull request that runs code on your machine. Untrusted code needs disposable runners.
