Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,8 @@ To enable {% data variables.product.prodname_github_connect %}, you configure a

After you configure the connection between {% data variables.location.product_location %} and {% data variables.product.prodname_ghe_cloud %}, you can enable individual features of {% data variables.product.prodname_github_connect %}.

If you're connecting to an enterprise on **{% data variables.enterprise.data_residency_site %}**:

{% data reusables.github-connect.what-is-available-ghecom %}

| Feature | Description | More information |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ You can access additional features and workflows on {% data variables.location.p
## Prerequisites

* **Administrative access:** You need administrative access to both an enterprise account on {% data variables.enterprise.data_residency_site %} and a {% data variables.product.prodname_ghe_server %} instance.
* **Version requirement:** Your {% data variables.product.prodname_ghe_server %} instance must run {% data variables.product.prodname_ghe_server %} 3.12 or later.
* **Version requirement:** To enable {% data variables.product.prodname_github_connect %} for {% data variables.enterprise.data_residency_site %}, your {% data variables.product.prodname_ghe_server %} instance must be on version 3.12 or later. Certain individual features of {% data variables.product.prodname_github_connect %} require later versions. See [AUTOTITLE](/admin/configuring-settings/configuring-github-connect/about-github-connect#github-connect-features).
* **Proxy configuration:** If using a proxy server, allow connectivity to the following {% data variables.enterprise.data_residency_site %} hostnames (replace SUBDOMAIN with your enterprise's subdomain).

* `{% data variables.enterprise.data_residency_domain %}`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -95,9 +95,7 @@ To allow people to use namespaces that match actions you have used from {% data

You can use {% data variables.product.prodname_github_connect %} to connect to {% data variables.enterprise.data_residency_site %} from {% data variables.product.prodname_ghe_server %}.

* {% data variables.product.prodname_server_statistics %} is not available.
* {% data variables.product.prodname_dotcom_the_website %} actions are not available.
* Automatic user license sync requires {% data variables.product.prodname_ghe_server %} version 3.15 or later.
{% data reusables.github-connect.what-is-available-ghecom %}

To enable {% data variables.product.prodname_github_connect %}, you must configure your {% data variables.product.prodname_ghe_server %} instance to connect to your {% data variables.enterprise.data_residency_site %} subdomain. See [AUTOTITLE](/enterprise-server@latest/admin/configuring-settings/configuring-github-connect/enabling-github-connect-for-ghecom).

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ category:

By default, {% data variables.product.prodname_actions %} workflows on {% data variables.product.prodname_ghe_server %} cannot use actions directly from {% data variables.product.prodname_dotcom_the_website %} or [{% data variables.product.prodname_marketplace %}](https://github.com/marketplace?type=actions). To make public actions from {% data variables.product.prodname_dotcom_the_website %} available on your enterprise instance, you can use {% data variables.product.prodname_github_connect %} to integrate {% data variables.product.prodname_ghe_server %} with {% data variables.product.prodname_ghe_cloud %}.

If your cloud deployment is on {% data variables.enterprise.data_residency_site %}, {% data variables.product.prodname_github_connect %} can still resolve public actions from {% data variables.product.prodname_dotcom_the_website %}. This requires {% data variables.product.prodname_ghe_server %} version 3.20.6 or later, or any feature release from 3.21.0.

{% data reusables.actions.self-hosted-runner-networking-to-dotcom %}

Alternatively, if you want stricter control over which actions are allowed in your enterprise, you can manually download and sync public actions onto your enterprise instance using the `actions-sync` tool. For more information, see [AUTOTITLE](/admin/managing-github-actions-for-your-enterprise/managing-access-to-actions-from-githubcom/manually-syncing-actions-from-githubcom).
Expand All @@ -34,7 +36,7 @@ If a user has already created an organization and repository in your enterprise

Before enabling access to public actions from {% data variables.product.prodname_dotcom_the_website %} for your enterprise, you must:
* Configure {% data variables.location.product_location %} to use {% data variables.product.prodname_actions %}. For more information, see [AUTOTITLE](/admin/managing-github-actions-for-your-enterprise/getting-started-with-github-actions-for-your-enterprise/getting-started-with-github-actions-for-github-enterprise-server).
* Enable {% data variables.product.prodname_github_connect %}. For more information, see [AUTOTITLE](/admin/configuring-settings/configuring-github-connect/enabling-github-connect-for-githubcom).
* Enable {% data variables.product.prodname_github_connect %}. For more information, see [AUTOTITLE](/admin/configuring-settings/configuring-github-connect/enabling-github-connect-for-githubcom) or [AUTOTITLE](/admin/configuring-settings/configuring-github-connect/enabling-github-connect-for-ghecom).

{% data reusables.enterprise-accounts.access-enterprise %}
{% data reusables.enterprise-accounts.github-connect-tab %}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -615,7 +615,7 @@ Package manager | YAML value | Supported versions |
| {% endif %} |
| Swift | `swift` | v5, v6 |
| Terraform | `terraform` | >= 0.13, <= 1.15.x |
| uv | `uv` | v0 |
| uv | `uv` | v0.11 |
| {% ifversion dependabot-vcpkg-support %} |
| vcpkg | `vcpkg` | Not applicable |
| {% endif %} |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -117,3 +117,5 @@ You can view your current {% data variables.product.prodname_actions %} usage fo
{% data variables.copilot.copilot_pro_short %} and {% data variables.copilot.copilot_pro_plus_short %} subscribers on **existing annual billing plans** using the **request-based billing** model have different model multipliers. See [AUTOTITLE](/copilot/reference/copilot-billing/request-based-billing-legacy/model-multipliers-for-annual-plans).

[^gemini-flash-promo]: {% data variables.copilot.copilot_gemini_36_flash %} and {% data variables.copilot.copilot_gemini_37_flash %} are available at the promotional pricing of $0.75 per 1M input tokens, $0.075 per 1M cached input tokens, and $3.75 per 1M output tokens through December 31, 2026.

[^gpt-56-sol-promo]: {% data variables.copilot.copilot_gpt_56_sol %} is available at promotional pricing, 50% off standard rates, through September 3, 2026. The default tier is $2.50 per 1M input tokens, $0.25 per 1M cached input tokens, $3.125 per 1M cache write tokens, and $15.00 per 1M output tokens. The long context tier is $5.00 per 1M input tokens, $0.50 per 1M cached input tokens, $6.25 per 1M cache write tokens, and $22.50 per 1M output tokens.
1 change: 1 addition & 0 deletions content/site-policy/privacy-policies/github-cookies.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ GitHub | `__Host-user_session_same_site` | This cookie is set to ensure that bro
GitHub | `logged_in` | This cookie is used to signal to us that the user is already logged in. | One year
GitHub | `marketplace_repository_ids` | This cookie is used for the marketplace installation flow. | One hour
GitHub | `marketplace_suggested_target_id` | This cookie is used for the marketplace installation flow. | One hour
GitHub | `notifications_web_disabled` | This cookie caches whether web notifications are disabled, so the global navigation notifications indicator can be rendered without an additional lookup. | One month
GitHub | `_octo` | This cookie is used for session management including caching of dynamic content, conditional feature access, support request metadata, and first party analytics. | One year
GitHub | `org_transform_notice` | This cookie is used to provide notice during organization transforms. | One hour
GitHub | `private_mode_user_session` | This cookie is used for Enterprise authentication requests. | Two weeks
Expand Down
2 changes: 1 addition & 1 deletion data/release-notes/enterprise-server/3-20/0.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ sections:
notes:
# https://github.com/github/releases/issues/5765
- |
Site administrators can enable GitHub Connect to resolve open source actions from GitHub.com, even when their GHES instance is connected to a data-resident enterprise on GHE.com. This enables hybrid deployment scenarios during migration to GHE.com. This feature is in public preview and subject to change.
Site administrators can enable GitHub Connect to resolve open source actions from GitHub.com, even when their GHES instance is connected to a data-resident enterprise on GHE.com. This enables hybrid deployment scenarios during migration to GHE.com. This feature is in public preview and subject to change. **Note: This feature was temporarily disabled in 3.20.1 and is generally available from 3.20.6.** [Updated: 2026-08-21]
- heading: Code scanning
notes:
Expand Down
2 changes: 1 addition & 1 deletion data/release-notes/enterprise-server/3-20/1.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ sections:
- |
When applying a hotpatch or running a configuration with `ghe-config-apply`, the configuration run could fail with "ERROR: Restoring CodeQL Action release tags" if internal Git services were not yet fully available. The error message "SpokesAPI::TwirpServerError: unavailable" appeared in logs.
- |
On instances connected to GitHub Enterprise Cloud with data residency, the "GitHub.com actions" setting appeared in the GitHub Connect configuration despite this feature not being available for data residency deployments.
On instances connected to GitHub Enterprise Cloud with data residency, the "GitHub.com actions" setting appeared in the GitHub Connect configuration despite this feature not being available for data residency deployments. **Note: This feature is available from 3.20.6.** [Updated: 2026-08-21]
- |
On instances with GitHub Actions enabled, errors appeared in logs related to missing Elasticsearch field mappings for workflow runs. The workflow run data included an `archived` field that was not defined in the Elasticsearch index mapping.
- |
Expand Down
5 changes: 4 additions & 1 deletion data/release-notes/enterprise-server/3-20/6.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,13 @@
date: '2026-08-05'
sections:
features:
- |
Site administrators can enable GitHub Connect to resolve open source actions from GitHub.com, even when their GHES instance is connected to a data-resident enterprise on GHE.com. This feature is now generally available. See [AUTOTITLE](/admin/configuring-settings/configuring-github-connect/enabling-github-connect-for-ghecom). [Updated: 2026-08-21]
security_fixes:
- |
**HIGH**: A path traversal vulnerability allowed an unauthenticated attacker to delete the user storage directory on the GitHub Enterprise Server instance, including Git LFS objects, release assets, attachments, and avatars, via the unsanitized X-GitHub-Request-Id request header. Exploitation required network access to the instance and worked when private mode was enabled. GitHub has requested CVE ID [CVE-2026-17556](https://www.cve.org/cverecord?id=CVE-2026-17556) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
- |
Some internal, auto-generated secrets were not redacted when users compiled a support bundle.
Some internal, auto-generated secrets were not redacted when users compiled a support bundle.
bugs:
- |
On a {% data variables.product.prodname_ghe_server %} cluster upgrade, if all Consul server nodes restarted concurrently, the cluster could lose its Nomad leader and fail to recover, causing the upgrade to loop and fail rather than complete.
Expand Down
4 changes: 2 additions & 2 deletions data/reusables/dependabot/supported-package-managers.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,9 +56,9 @@ pipenv | `pip` | 2024.4.1 | {% octicon "check" aria-label="
[Swift](#swift) | `swift` | v5, v6 | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} (git only) | {% octicon "x" aria-label="Not supported" %} |
[Terraform](#terraform) | `terraform` | >= 0.13, <= 1.15.x | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | Not applicable |
| {% ifversion dependabot-uv-security-support %} |
uv | `uv` | v0 | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | Not applicable |
uv | `uv` | v0.11 | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | Not applicable |
| {% elsif dependabot-uv-support %} |
uv | `uv` | v0 | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | Not applicable |
uv | `uv` | v0.11 | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | Not applicable |
| {% endif %} |
| {% ifversion dependabot-vcpkg-support %} |
[vcpkg](#vcpkg) | `vcpkg` | Not applicable | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | Not applicable |
Expand Down
9 changes: 3 additions & 6 deletions data/reusables/github-connect/what-is-available-ghecom.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,3 @@
{% ifversion ghecom-github-connect %}
If you're connecting to an enterprise on **{% data variables.enterprise.data_residency_site %}**:
* Server Statistics is not available.
* {% data variables.product.prodname_dotcom_the_website %} actions are not available.

{% endif %}
* {% data variables.product.prodname_server_statistics %} is not available.
* Automatic user license sync requires {% data variables.product.prodname_ghe_server %} version 3.15 or later.
* Actions from {% data variables.product.prodname_dotcom_the_website %} require {% data variables.product.prodname_ghe_server %} version 3.20.6 or later, or any feature release from 3.21.0.
20 changes: 10 additions & 10 deletions data/tables/copilot/models-and-pricing.yml
Original file line number Diff line number Diff line change
Expand Up @@ -130,27 +130,27 @@
output: $1.80
cache_write: $0.50

- model: GPT-5.6 Sol
- model: 'GPT-5.6 Sol[^gpt-56-sol-promo]'
provider: openai
release_status: GA
category: Powerful
threshold: '≤ 272K'
tier: Default
input: $5.00
cached_input: $0.50
output: $30.00
cache_write: $6.25
input: $2.50
cached_input: $0.25
output: $15.00
cache_write: $3.125

- model: GPT-5.6 Sol
- model: 'GPT-5.6 Sol[^gpt-56-sol-promo]'
provider: openai
release_status: GA
category: Powerful
threshold: '> 272K'
tier: 'Long context'
input: $10.00
cached_input: $1.00
output: $45.00
cache_write: $12.50
input: $5.00
cached_input: $0.50
output: $22.50
cache_write: $6.25

- model: GPT-5.6 Terra
provider: openai
Expand Down
Loading