Back to feed
GitHub Changelog
GitHub Changelog
7/28/2026
GitHub Actions holds potentially malicious workflows for approval

GitHub Actions holds potentially malicious workflows for approval

Short summary

GitHub is now holding potentially malicious GitHub Actions workflows for approval after recent supply chain attacks used compromised credentials to push workflows that steal CI/CD secrets. The feature targets public repositories where attackers exploit stolen tokens to inject malicious automation. This is a defensive measure to prevent credential theft via compromised CI/CD pipelines.

  • Supply chain attacks exploit stolen GitHub credentials to push malicious Actions workflows
  • Malicious workflows steal CI/CD credentials and enable further attacks
  • GitHub now holds suspicious workflows for manual approval before execution

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more