- GitHub Actions now automatically holds potentially malicious workflows for manual approval before execution.
- This protects public repositories from supply‑chain attacks that use compromised credentials to inject harmful CI/CD workflows.
- Repository owners can review, approve, or reject flagged workflows to prevent credential theft and further exploitation.