All updates
github: GitHub Actions holds potentially malicious workflows for approval
Jul 28, 2026
GitHub Actions now detects potentially malicious workflow changes in public repositories and requires approval before they run. The change is intended to reduce supply-chain abuse from compromised credentials used to add workflows that steal CI/CD secrets or perform follow-on attacks.
- Source: GitHub