Skip to content

GitHub Actions holds potentially malicious workflows for approval

UpdateVerifiedAdded Sep 22, 2026

Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these attacks, GitHub Actions now holds certain workflow runs for approval before they start.

Read GitHub's release notes

https://github.blog/changelog/2026-07-28-github-actions-holds-potentially-malicious-workflows-for-approval

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Actions releases

GitHub Actions

Reference same-repository actions with self-repository syntax

Update
GitHub Actions

Xcode 27 runner image now in public preview

Preview
GitHub Actions

Actions retention will cover checks, workflow runs, and statuses

Update
GitHub Actions

Read-only Actions cache for untrusted triggers

Update

Also shipped on Jul 28, 2026

Snowflake Native Apps support for Virtual Private Snowflake on AWS for apps with containers (General availability)

VercelVercel platform

Vercel Connect now supports Custom Environments

Preview

Weekly: the week's data and AI releases, Tuesday mornings.