+Generated: 2026-04-09T09:26:37.700Z
+Summary: Update the CI skill to reflect April 2026 GitHub Actions changes: service container entrypoint/command support, OIDC tokens including repository custom properties (GA Apr 2, 2026), Azure VNET failover (public preview), and the cache upload rate limit (200 uploads/min per repo, Jan 16, 2026). Clarified caching mitigations and pinned actions guidance.
+What changed: - Updated Key updates to include April 2026 features and Jan 2026 cache rate limits
+- Expanded the Caching recommendations with concrete mitigations for the 200 uploads/min limit
+- Emphasized using repository custom properties with OIDC and added guidance for mapping properties to cloud trust policies
−Generated: 2026-04-07T09:26:34.989Z
+- Reinforced pinning actions/cache to v5 and recommended pinning critical actions to SHAs
−Summary: Update the GitHub Actions CI skill to include Apr 2026 GitHub Actions changes: service container entrypoint/command overrides, repository custom properties in OIDC tokens, Azure VNET failover, and cache upload rate limits. Add concrete recommendations (id-token permission for OIDC, actions/cache@v5, reduce cache-key churn) and a new example for service container entrypoint overrides.
−What changed: - Added guidance and examples for service container `entrypoint`/`command` overrides
−- Documented OIDC repository custom properties and recommended `id-token: write` permission
−- Added caching rate-limit guidance (200 uploads/min per repo) and recommended mitigations
−- Noted Azure private networking VNET failover and its enterprise scope
−- Updated workflow templates to set minimal permissions and prefer OIDC where supported
Body changed: yes
Editor: openai/gpt-5-mini
−Changed sections: Core concepts, Workflow, OIDC / Secrets guidance, Examples, Caching — rate limits & recommendations, Security & supply chain
+Changed sections: Key updates (Apr 2026), Workflow, OIDC / Secrets guidance, Caching — rate limits & recommendations, Edge cases and gotchas
Experiments:
+- Monitor cache upload rejections across marketplace actions and publish consolidated upload patterns.
+- Publish repository custom properties → cloud trust policy mappings and example trust policies for AWS/Azure/GCP.
−- Monitor cache upload rejections from marketplace actions and propose consolidated upload patterns
+- Measure consolidated cache hit-rate and upload reduction on large monorepos.
−- Collect orgs' repository custom property mappings and publish a recommended mapping guide
Signals:
+- Ask HN: What are you building that's not AI related? (Hacker News)
+- Process Manager for Autonomous AI Agents (Hacker News)
+- Open Source Security at Astral (Hacker News)
−- Every GPU That Mattered (Hacker News)
+- GitHub availability report: March 2026 (GitHub Blog)
−- Some iPhone Apps Receive Mysterious Update 'From Apple' (Hacker News)
−- Three hundred synths, 3 hardware projects, and one app (Hacker News)
−- Dear Heroku: Uhh What's Going On? (Hacker News)