GitHub Actions holds potentially malicious workflows for approval
Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these attacks, GitHub Actions now holds certain workflow runs for approval before they start.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-28-github-actions-holds-potentially-malicious-workflows-for-approval
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Actions releases
Reference same-repository actions with self-repository syntax
UpdateGovernanceObservabilityDeveloper tools
Xcode 27 runner image now in public preview
PreviewData integrationObservabilityDeveloper tools
CodeQL 2.26.3 improves GitHub Actions queries and JavaScript modeling
UpdateSQLSecurityDeveloper tools
Actions retention will cover checks, workflow runs, and statuses
UpdateObservabilityDeveloper tools
Also shipped on Jul 28, 2026
Python UDTFs in Unity Catalog are now generally available
GASQLGovernanceObservability
Vercel Connect now supports Custom Environments
PreviewPricingData integrationBI