Azure / Azure/functions-action
Request for Post-Incident Transparency Regarding Azure/functions-action Outage
- Dominant language
- TypeScript
- Stars
- 184
- Forks
- 92
- PR merge metrics
- No merged PRs in 30d
Description
### Summary
On June 5, 2026, the `Azure/functions-action` repository became unavailable, causing deployment failures for GitHub Actions workflows relying on `Azure/functions-action@v1`.
Public discussions and security reports have linked the broader repository disablements affecting Azure-related repositories to the recent Miasma supply-chain incident. At the same time, public communications have described the situation as an "internal management issue" under investigation.
#### References:
- [The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds](https://opensourcemalware.com/blog/miasma-reaches-azure)
- [GitHub action `Azure/functions-action` down
](https://learn.microsoft.com/en-my/answers/questions/5912595/github-action-azure-functions-action-down)
- [Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents](https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents#global-cicd-breakage-azurefunctions-action-down)
### Questions
Would the Azure Functions team be willing to provide a post-incident summary addressing the following points?
1. Was `Azure/functions-action` directly affected by the security incident, or was it disabled as a precautionary measure?
1. What was the root cause of the repository unavailability?
1. Were any published action tags, releases, or deployment artifacts impacted?
1. Are there recommended mitigations for users who relied on `Azure/functions-action@v1` ?
1. Will there be any changes to versioning guidance (for example, stronger recommendations around immutable commit SHAs instead of mutable tags)?
1. Is a public incident report or postmortem planned?
Many organizations depend on `Azure/functions-action` for production deployments. Understanding the cause, scope, and remediation steps would help users assess risk, improve their supply-chain security posture, and prepare for similar situations in the future.
Thank you for any information the team can share once the investigation is complete.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.