CI Runner Audit
apache/magpie
Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.
Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PostHog/posthog-foss depot-github-runners --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/depot-github-runners .claude/skills/depot-github-runners && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .claude/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runnersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PostHog/posthog-foss depot-github-runners --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/depot-github-runners .agents/skills/depot-github-runners && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .agents/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PostHog/posthog-foss depot-github-runners --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/depot-github-runners .cursor/skills/depot-github-runners && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .cursor/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PostHog/posthog-foss.git --path .agents/skills/depot-github-runners--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PostHog/posthog-foss depot-github-runners --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/depot-github-runners .gemini/skills/depot-github-runners && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .gemini/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PostHog/posthog-foss depot-github-runnersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/depot-github-runners .github/skills/depot-github-runners && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .github/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill depot-github-runners -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PostHog/posthog-foss depot-github-runners --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/depot-github-runners .opencode/skills/depot-github-runners && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "depot-github-runners" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/depot-github-runners into .opencode/skills/depot-github-runners/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "depot-github-runners", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
depot-github-runnersConfigures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.
Depot GitHub Runners is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners. Use when setting up or migrating GitHub Actions workflows to use Depot runners, choosing runner sizes (CPU/RAM), configuring runs-on labels, setting up ARM or Windows or macOS runners, troubleshooting GitHub Actions runner issues, configuring egress filtering, using Depot Cache with GitHub Actions, or running Dagger/Dependabot on Depot runners. Also use when the user mentions depot-ubuntu, depot-windows…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `UPSTREAM.md`).
It sits in DevOps & Cloud, covering CI/CD and Dependency management. It works with GitHub, GitHub Actions, macOS and PostHog. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
turbobazelFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
depot.devFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DEPOT_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Depot GitHub Runners loads about 2.8k tokens when it runs. Until then it costs about 176 tokens; SKILL.md has 942 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 942 words, ~2,805 tokens.
.claude/skills/depot-github-runners/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Depot provides managed, ephemeral, single-tenant GitHub Actions runners. Drop-in replacement for GitHub-hosted runners — change the runs-on label and everything else stays the same.
Requirement: Repository must be owned by a GitHub organization (not a personal account).
<!-- PostHog-local section. Keep it when resyncing from upstream; see UPSTREAM.md. -->
Depot runners keep GitHub Actions as the engine, so the workflow lives in .github/workflows/ and the checks still come from the github-actions app.
Depot CI is a different product: it reads .depot/workflows/, which GitHub Actions ignores, and posts its own check runs from the depot-code-access app.
Use the depot-ci skill for that one.
Its references/posthog-check-run-semantics.md compares what each engine reports for a skipped, empty-matrix or continue-on-error job, and how GitHub and the Trunk merge queue score those conclusions.
<!-- End PostHog-local section. -->
runs-on in your workflow filesIf a user belongs to multiple organizations and expected repos/settings/runners are not visible, verify Depot org context first:
depot org show # Current org ID
depot org list # Orgs the user belongs to
depot org switch <org-id> # Optional: set default orgFor commands that support it, pass --org <org-id> to target the org where the workflow/repo lives.
Use a single label. Format: depot-{os}-{version}[-{arch}][-{size}]
| Label | CPUs | RAM | Disk | $/min | Minutes multiplier |
|---|---|---|---|---|---|
depot-ubuntu-24.04 | 2 | 8 GB | 100 GB | $0.004 | 1x |
depot-ubuntu-24.04-4 | 4 | 16 GB | 130 GB | $0.008 | 2x |
depot-ubuntu-24.04-8 | 8 | 32 GB | 150 GB | $0.016 | 4x |
depot-ubuntu-24.04-16 | 16 | 64 GB | 180 GB | $0.032 | 8x |
depot-ubuntu-24.04-32 | 32 | 128 GB | 200 GB | $0.064 | 16x |
depot-ubuntu-24.04-64 | 64 | 256 GB | 250 GB | $0.128 | 32x |
The minutes multiplier is the billing driver: billed minutes = elapsed minutes × multiplier, so larger runners consume your included minutes faster.
Ubuntu 22.04 also available: depot-ubuntu-22.04, depot-ubuntu-22.04-4, etc.
Same sizes and pricing as Intel. Add -arm suffix:
depot-ubuntu-24.04-arm, depot-ubuntu-24.04-arm-4, depot-ubuntu-24.04-arm-8, etc.
| Label | CPUs | RAM | $/min | Minutes multiplier |
|---|---|---|---|---|
depot-windows-2025 | 2 | 8 GB | $0.008 | 2x |
depot-windows-2025-4 | 4 | 16 GB | $0.016 | 4x |
depot-windows-2025-8 through -64 | 8–64 | 32–256 GB | $0.032–$0.256 | 8x–64x |
Windows Server 2022 also available: depot-windows-2022, etc.
Windows limitation: No Hyper-V (AWS EC2 limitation), so Docker workloads that require it are unlikely to work.
| Label | CPUs | RAM | Disk | $/min |
|---|---|---|---|---|
depot-macos-26 | 8 | 24 GB | 400 GB | $0.08 |
depot-macos-15 / depot-macos-latest | 8 | 24 GB | 400 GB | $0.08 |
depot-macos-14 | 8 | 24 GB | 400 GB | $0.08 |
macOS is NOT fully elastic — fixed pool with FIFO queuing.
depot-ubuntu-latest → Ubuntu 24.04, depot-windows-latest → Windows 2025, depot-macos-latest → macOS 15
jobs:
build:
# Before:
# runs-on: ubuntu-latest
# After:
runs-on: depot-ubuntu-24.04-4
steps:
- uses: actions/checkout@v4
- run: npm ci
- run: npm test# ❌ WRONG — multiple labels cause stability issues
runs-on: [self-hosted, depot-ubuntu-24.04]
# ✅ CORRECT — always use a single Depot runner label
runs-on: depot-ubuntu-24.04-4Actions using the GitHub Actions cache API automatically use Depot Cache — no config changes needed. This includes actions/cache, actions/setup-node, actions/setup-python, actions/setup-java, and any action using @actions/cache.
Pre-configured build tool caches (zero config on Depot runners):
| Tool | What's pre-configured |
|---|---|
| Turborepo | TURBO_API env var set — just run turbo build |
| Bazel | ~/.bazelrc pre-populated — just run bazel build //... |
| sccache | SCCACHE_WEBDAV_ENDPOINT set — use RUSTC_WRAPPER: 'sccache' |
| Maven | settings.xml pre-populated (cache id depot-cache) |
| Pants | pants.toml pre-configured — just run pants package :: |
| moonrepo | Env vars set — just run moon run build |
Cache behavior: repository-scoped, no branch isolation, encrypted, up to 1000 MiB/s throughput, configurable retention (7/14/30 days).
To disable auto-cache: org settings → turn off "Allow Actions jobs to automatically connect to Depot Cache."
Deprecated: Dagger Engine support on Depot GitHub Actions Runners is being deprecated and will be removed in a future update. Don't recommend this integration for new workflows.
runs-on: depot-ubuntu-latest,dagger=0.18.4Launches a dedicated Dagger Engine VM with persistent NVMe cache. Dagger CLI pre-installed. Additional $0.04/min.
Configure in org settings → GitHub Actions Runners → Egress Rules. Set default rule to Allow or Deny, then add specific allow/deny rules for IPs, CIDRs, or hostnames. Deny rules take precedence over Allow rules. Loopback traffic (127.0.0.1, ::1) is always allowed, and Depot auto-allowlists depot.dev domains, GitHub Actions service IPs, and AWS service IPs. Hostnames in rules are resolved and pinned in /etc/hosts. Container builds with depot build work with egress filtering enabled — Depot adds BuildKit machine IPs to the allowlist as they're allocated. Not supported on macOS or Windows. Incompatible with Tailscale.
Use Tailscale when jobs need to reach private services (internal APIs, databases, private subnets) without static IP allowlists.
How it works on Depot:
tag:depot-runner).Setup:
tag:depot-runner) under tagOwners.Keys > Auth Keys write scope and choose that tag.tag:depot-runner to access target hosts/subnets.ACL examples:
{
"acls": [
{
"action": "accept",
"src": ["tag:depot-runner"],
"dst": ["database-hostname"]
}
]
}{
"acls": [
{
"action": "accept",
"src": ["tag:depot-runner"],
"dst": ["192.0.2.0/24:*"]
}
]
}Reference docs:
Enable "Dependabot on self-hosted runners" in GitHub org settings. Jobs auto-run on depot-ubuntu-latest.
Important: OIDC is not supported for Dependabot. Use token: input with a DEPOT_TOKEN secret instead.
steps:
- uses: actions/checkout@v4
- uses: mxschmitt/action-tmate@v3
- run: npm test| Error | Fix |
|---|---|
| "No space left on device" | OS uses ~70 GB disk; upgrade to larger runner or clean disk in workflow |
| "Failed to open the device 'kvm'" / "Could not access KVM kernel module" | Runners don't provide /dev/kvm; move KVM/QEMU/Android-emulator jobs to Depot CI, where nested virtualization is enabled by default |
| "Lost communication with server" | Check status.depot.dev; check org usage caps |
| "Operation was canceled" | Manual cancel, concurrency cancel-in-progress, or OOM — check memory in dashboard |
| "Unable to get ACTIONS_ID_TOKEN_REQUEST_URL" | Dependabot doesn't support OIDC — use DEPOT_TOKEN secret |
| Workflows not starting | Verify single runner label; check runner group allows the repo; verify Depot GitHub App permissions |
| Stuck workflows | Force cancel via GitHub API: POST /repos/{owner}/{repo}/actions/runs/{id}/force-cancel |
© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/depot-github-runners of PostHog/posthog-foss.
Open the folder on GitHubat commit 2c48221
Depot GitHub Runners next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Depot GitHub Runners this skillPostHog/posthog-foss | 721 | — | ~2.8k | Automated safety check: Pass | MIT | |
| CI Runner Auditapache/magpie | 110 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Running GitHub Actions Efficientlykajisho5/ffmpeg-skill | 1.9k | — | ~3.3k | Automated safety check: Notes | MIT | |
| Release Publishbkywksj/knowledge-base | 330 | — | ~6.2k | Automated safety check: Pass | Custom licence | |
| Sicurezza GitHubccplugins/awesome-claude-code-plugins | 967 | — | ~486 | Automated safety check: Notes | Apache-2.0 | |
| GitHub Actionsbobmatnyc/claude-mpm | 155 | — | ~6.9k | Automated safety check: Pass | Custom licence |
apache/magpie
Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.
kajisho5/ffmpeg-skill
Cut GitHub Actions minutes and wall-clock time without losing coverage — the OS billing multiplier (macOS 10x / Windows 2x / Linux 1x), trigger hygiene that stops push+pullrequest double-firing…
bkywksj/knowledge-base
发布 Tauri 桌面应用新版本,处理版本号同步、Git tag、GitHub Actions 构建、Release 仓库产物同步、Cloudflare R2 上传、update.json 生成、自动更新发布和文档站重建。
ccplugins/awesome-claude-code-plugins
Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.
bobmatnyc/claude-mpm
GitHub Actions CI/CD workflows for automating build, test, and deployment
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
PostHog/posthog-foss
Author useful, low-noise log alerts on services in a PostHog project.
PostHog/posthog-foss
Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…
PostHog/posthog-foss
Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).
PostHog/posthog-foss
Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.
PostHog/posthog-foss
Debug and inspect LLM/AI agent traces using PostHog's MCP tools.
PostHog/posthog-foss
Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.
Works with
Categories
Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners. Depot GitHub Runners is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Configures Depot-managed GitHub Actions runners as a drop-in replacement for GitHub-hosted runners.
Depot GitHub Runners fits situations like: migrating GitHub Actions workflows to use Depot runners; choosing runner sizes (CPU/RAM); configuring runs-on labels; troubleshooting GitHub Actions runner issues.
Run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a claude-code`. Or copy the skill folder (.agents/skills/depot-github-runners in PostHog/posthog-foss) into .claude/skills/depot-github-runners in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a codex`. Or copy the skill folder (.agents/skills/depot-github-runners in PostHog/posthog-foss) into .agents/skills/depot-github-runners in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill depot-github-runners -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/depot-github-runners, .gemini/skills/depot-github-runners, .github/skills/depot-github-runners and .opencode/skills/depot-github-runners in your project.
Going by SKILL.md and its folder, Depot GitHub Runners needs the command-line tools its instructions call (turbo and bazel) and credentials named DEPOT_TOKEN. Our summary lists: Docker; A credential in DEPOT_TOKEN.
SKILL.md names 1 domain. As links in the text: depot.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Depot GitHub Runners is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Depot GitHub Runners: CI Runner Audit (apache/magpie, 110 stars), Running GitHub Actions Efficiently (kajisho5/ffmpeg-skill, 1.9k stars), Release Publish (bkywksj/knowledge-base, 330 stars) and Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 967 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.
Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.