Scheduled Workflows with cron

The schedule event starts a workflow from POSIX cron expressions (minute, hour, day of month, month, weekday), in UTC unless an entry names an IANA timezone (added in March 2026). BookNest's nightly.yml runs npm 2,036 audit --omit=dev --audit-level=high, which catches advisories published since the last commit:

The on: block of .github/workflows/nightly.ymlYAML
on:
  schedule:
    - cron: "*/15 * * * *"        # every 15 minutes while you watch; nightly: "30 2 * * *"
      timezone: "Asia/Kuala_Lumpur"
    - cron: "5,35 * * * *"        # the same idea in UTC, twice an hour
  workflow_dispatch:

Schedules fire at most every 5 minutes, only from the default branch's workflow file, and "can be delayed during periods of high loads", especially on the hour, hence minutes such as 5 and 35. Delays can be long: after pull request #15 merged at 11:28 UTC, no scheduled run had arrived by 13:58, ten due times later, even after a UTC-only entry was added at 13:13. workflow_dispatch is the backup and the way to test on demand:

Running the audit by hand, then disabling the scheduleShell
gh workflow run nightly.yml
gh run view 36142214377 --log | cut -f3 | sed 's/^[^ ]* //' | grep -E '^(found|Audited)'
gh workflow disable nightly.yml && gh workflow list --all | grep Nightly
Output
https://github.com/binarybehemoth/booknest/actions/runs/36142214377
found 0 vulnerabilities
Audited 21:38 Asia/Kuala_Lumpur for workflow_dispatch
Nightly audit  disabled_manually  366900471

Never rely on a schedule for anything time-critical. GitHub 29 disables a public repository's schedules after 60 idle days; disable demo schedules yourself.