GitHub Changelog
7/28/2026

GitHub Actions holds potentially malicious workflows for approval
Short summary
GitHub is now holding potentially malicious GitHub Actions workflows for approval after recent supply chain attacks used compromised credentials to push workflows that steal CI/CD secrets. The feature targets public repositories where attackers exploit stolen tokens to inject malicious automation. This is a defensive measure to prevent credential theft via compromised CI/CD pipelines.
- •Supply chain attacks exploit stolen GitHub credentials to push malicious Actions workflows
- •Malicious workflows steal CI/CD credentials and enable further attacks
- •GitHub now holds suspicious workflows for manual approval before execution
Generated with AI, which can make mistakes.
Is this a good recommendation for you?
