Skip to content

GitHub Actions holds potentially malicious workflows for approval

UpdateVerifiedAdded Sep 22, 2026

Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these attacks, GitHub Actions now holds certain workflow runs for approval before they start.

Topics: Observability, Developer tools

GitHub's release notes

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Actions releases

Every GitHub Actions release

Also shipped on Jul 28, 2026

GitHub in July 2026

Weekly: the week's data and AI releases, Tuesday mornings.