Skip to content

Read-only Actions cache for untrusted triggers

UpdateVerifiedAdded Sep 22, 2026

GitHub Actions now issues read-only cache tokens to the default branch for workflow events that can be triggered without write permissions to the repository. This applies least privilege to the cache and prevents common privilege-escalation paths through cache poisoning.

Read GitHub's release notes

https://github.blog/changelog/2026-06-26-read-only-actions-cache-for-untrusted-triggers

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Actions releases

GitHub Actions

More control over your GitHub-hosted runners

Update
GitHub Actions

Actions steps can now be run in parallel

Update
GitHub Actions

Red Hat Enterprise Linux runner images are now in public preview

Preview
GitHub Actions

Xcode 27 runner image now in public preview

Preview
GitHub Actions

GitHub Actions holds potentially malicious workflows for approval

Update
GitHub Actions

Reference same-repository actions with self-repository syntax

Update

Also shipped on Jun 26, 2026

Support for variables in semantic views (General availability)

GA
DatabricksLakeflow

Microsoft Dynamics 365 connector (GA)

GA

Weekly: the week's data and AI releases, Tuesday mornings.