CHANGELOG

GitHub Actions holds potentially malicious workflows for approval

Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public repositories from these… The post GitHub Actions holds…

Source GitHub ChangelogPublished 7d ago · Jul 28, 2026Posted on Threads

What we hold

Source
GitHub Changelog