megachangelog
Security

GitHub Actions holds potentially malicious workflows for approval

GitHub is implementing a security feature that requires approval for potentially malicious GitHub Actions workflows to protect public repositories from supply chain attacks that compromise CI/CD credentials.

Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these attacks, GitHub Actions now holds certain workflow runs for approval before they start.

When a workflow run is identified as potentially malicious and held, the workflow won’t execute until a repository collaborator with write access reviews and approves it. The approval must be submitted through an authenticated web session. Once approved, the workflow continues normally.

You don’t need to configure this protection; GitHub applies it automatically.

This protection currently applies to public repositories on github.com only. GitHub Enterprise Server doesn’t add this protection at this time.

The post GitHub Actions holds potentially malicious workflows for approval appeared first on The GitHub Blog.

securitygithub-actionssupply-chainci-cdworkflows

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →