Summary
On June 5, 2026, the Azure/functions-action repository became unavailable, causing deployment failures for GitHub Actions workflows relying on Azure/functions-action@v1.
Public discussions and security reports have linked the broader repository disablements affecting Azure-related repositories to the recent Miasma supply-chain incident. At the same time, public communications have described the situation as an "internal management issue" under investigation.
References:
Questions
Would the Azure Functions team be willing to provide a post-incident summary addressing the following points?
- Was
Azure/functions-action directly affected by the security incident, or was it disabled as a precautionary measure?
- What was the root cause of the repository unavailability?
- Were any published action tags, releases, or deployment artifacts impacted?
- Are there recommended mitigations for users who relied on
Azure/functions-action@v1 ?
- Will there be any changes to versioning guidance (for example, stronger recommendations around immutable commit SHAs instead of mutable tags)?
- Is a public incident report or postmortem planned?
Many organizations depend on Azure/functions-action for production deployments. Understanding the cause, scope, and remediation steps would help users assess risk, improve their supply-chain security posture, and prepare for similar situations in the future.
Thank you for any information the team can share once the investigation is complete.
Summary
On June 5, 2026, the
Azure/functions-actionrepository became unavailable, causing deployment failures for GitHub Actions workflows relying onAzure/functions-action@v1.Public discussions and security reports have linked the broader repository disablements affecting Azure-related repositories to the recent Miasma supply-chain incident. At the same time, public communications have described the situation as an "internal management issue" under investigation.
References:
Azure/functions-actiondownQuestions
Would the Azure Functions team be willing to provide a post-incident summary addressing the following points?
Azure/functions-actiondirectly affected by the security incident, or was it disabled as a precautionary measure?Azure/functions-action@v1?Many organizations depend on
Azure/functions-actionfor production deployments. Understanding the cause, scope, and remediation steps would help users assess risk, improve their supply-chain security posture, and prepare for similar situations in the future.Thank you for any information the team can share once the investigation is complete.