GitHub Actions holds potentially malicious workflows for approval
UpdateVerifiedAdded Sep 22, 2026
Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these attacks, GitHub Actions now holds certain workflow runs for approval before they start.
Topics: Observability, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Actions releases
Every GitHub Actions release| Date | Release | Type |
|---|---|---|
| Jul 30 | Reference same-repository actions with self-repository syntax Update | Update |
| Jul 16 | Xcode 27 runner image now in public preview Preview | Preview |
| Jul 8 | setup-java v5.5.0: signature verification, Kona JDK, and Maven fixes Update | Update |
| Aug 19 | CodeQL 2.26.3 improves GitHub Actions queries and JavaScript modeling Update | Update |
| Aug 20 | Windows 11 arm64 VS2026 image generally available GA | GA |
| Aug 20 | Separate GitHub Actions path for GitHub Code Quality GA | GA |
| Aug 27 | Actions retention will cover checks, workflow runs, and statuses Update | Update |
| Jun 26 | Read-only Actions cache for untrusted triggers Update | Update |