The schedule event starts a workflow from POSIX cron expressions (minute, hour, day of month, month, weekday), in UTC unless an entry names an IANA timezone (added in March 2026). BookNest's nightly.yml runs npm 2,036 audit --omit=dev --audit-level=high, which catches advisories published since the last commit:
on:
schedule:
- cron: "*/15 * * * *" # every 15 minutes while you watch; nightly: "30 2 * * *"
timezone: "Asia/Kuala_Lumpur"
- cron: "5,35 * * * *" # the same idea in UTC, twice an hour
workflow_dispatch:Schedules fire at most every 5 minutes, only from the default branch's workflow file, and "can be delayed during periods of high loads", especially on the hour, hence minutes such as 5 and 35. Delays can be long: after pull request #15 merged at 11:28 UTC, no scheduled run had arrived by 13:58, ten due times later, even after a UTC-only entry was added at 13:13. workflow_dispatch is the backup and the way to test on demand:
gh workflow run nightly.yml
gh run view 36142214377 --log | cut -f3 | sed 's/^[^ ]* //' | grep -E '^(found|Audited)'
gh workflow disable nightly.yml && gh workflow list --all | grep Nightlyhttps://github.com/binarybehemoth/booknest/actions/runs/36142214377 found 0 vulnerabilities Audited 21:38 Asia/Kuala_Lumpur for workflow_dispatch Nightly audit disabled_manually 366900471
Never rely on a schedule for anything time-critical. GitHub 29 disables a public repository's schedules after 60 idle days; disable demo schedules yourself.