Read-only Actions cache for untrusted triggers
GitHub Actions now issues read-only cache tokens to the default branch for workflow events that can be triggered without write permissions to the repository. This applies least privilege to the cache and prevents common privilege-escalation paths through cache poisoning.
Read GitHub's release noteshttps://github.blog/changelog/2026-06-26-read-only-actions-cache-for-untrusted-triggers
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Actions releases
Red Hat Enterprise Linux runner images are now in public preview
PreviewObservabilityDeveloper tools
Xcode 27 runner image now in public preview
PreviewData integrationObservabilityDeveloper tools
GitHub Actions holds potentially malicious workflows for approval
UpdateObservabilityDeveloper tools
Reference same-repository actions with self-repository syntax
UpdateGovernanceObservabilityDeveloper tools
CodeQL 2.26.3 improves GitHub Actions queries and JavaScript modeling
UpdateSQLSecurityDeveloper tools
Also shipped on Jun 26, 2026
Support for variables in semantic views (General availability)
GASQLObservabilityDeveloper tools
Databricks Runtime 19 (Beta): June 26, 2026
BetaGovernanceObservability