GitHub Changelog
7/28/2026

GitHub Actions holds potentially malicious workflows for approval
Short summary
GitHub announced a new security feature that holds potentially malicious GitHub Actions workflows for approval before execution. This addresses recent supply chain attacks where compromised credentials were used to push workflows that steal CI/CD secrets. The feature helps protect public repositories from credential theft and downstream attacks.
- •GitHub Actions now holds suspicious workflows for manual approval
- •Targets supply chain attacks using compromised credentials to steal CI/CD secrets
- •Applies to public repositories as a protective measure
Generated with AI, which can make mistakes.
Is this a good recommendation for you?

