DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

github: GitHub Actions holds potentially malicious workflows for approval

1 · Sujith Quintelier · July 29, 2026, 6:04 a.m.
github GitHub Actions Security Supply Chain
Summary
GitHub Actions now requires approval for potentially malicious workflow changes in public repositories to mitigate supply-chain abuse from compromised credentials, aiming to protect CI/CD secrets and prevent follow-on attacks.
Read full post on quintelier.dev →
MORE POSTS LIKE THIS
Docker OIDC connections for GitHub Actions available for Docker Orgs
Hub Docker · Jul 31, 2026
products docker hub
github: Safer pull_request_target defaults for GitHub Actions checkout
Sujith Quintelier · Jun 19, 2026
github GitHub Actions
Github PRs: do not submit
Thiago Perrotta · Apr 23, 2025
github pull-requests
Using GitHub Actions with Heroku Flow for additional Security Control
Heroku · Mar 27, 2025
GitHub Actions Heroku
GitHub adds approval checks for suspicious Actions workflows
Developer Tech · Jul 30, 2026
big-tech Build & Ship
Push images to Quay without a password
Red Hat · Jul 22, 2026
openid connect GitHub Actions
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google