G
Jul 28, 2026GitHub Actions freezes suspected-malicious workflow runs until a human signs off
GitHub has flipped Actions into a hold-first posture for workflow runs it flags as potentially malicious on public repositories: the run pauses until a collaborator with write access approves it from an authenticated web session. The change targets a wave of credential-theft attacks that push booby-trapped workflow files with stolen tokens.
Jul 28, 20264 min read0 reactions0 comments