Skip to content

Read-only Actions cache for untrusted triggers

UpdateVerifiedAdded Sep 22, 2026

GitHub Actions now issues read-only cache tokens to the default branch for workflow events that can be triggered without write permissions to the repository. This applies least privilege to the cache and prevents common privilege-escalation paths through cache poisoning.

Topics: Security, Developer tools

GitHub's release notes

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Actions releases

Every GitHub Actions release

Also shipped on Jun 26, 2026

GitHub in June 2026

Weekly: the week's data and AI releases, Tuesday mornings.