[{"data":1,"prerenderedAt":82},["ShallowReactive",2],{"blog-enhancing-security-github-actions-now-hold-potentially-malicious-workflows-for-approval":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"tags":11,"cover":17,"body":18,"_type":76,"_id":77,"_source":78,"_file":79,"_stem":80,"_extension":81},"/blog/enhancing-security-github-actions-now-hold-potentially-malicious-workflows-for-approval","blog",false,"","Enhancing Security: GitHub Actions Now Hold Potentially Malicious Workflows for Approval","GitHub introduces new approval steps to prevent malicious workflows in public repositories from compromising CI/CD credentials.","2026-07-29",[12,13,14,15,16],"github","security","devsecops","cicd","supplychain",true,{"type":19,"children":20,"toc":69},"root",[21,30,36,42,47,53,58,64],{"type":22,"tag":23,"props":24,"children":26},"element","h2",{"id":25},"the-rising-threat-supply-chain-attacks-via-github-actions",[27],{"type":28,"value":29},"text","The Rising Threat: Supply Chain Attacks via GitHub Actions",{"type":22,"tag":31,"props":32,"children":33},"p",{},[34],{"type":28,"value":35},"Recent supply chain attacks have exploited compromised GitHub credentials to introduce malicious workflows into GitHub Actions pipelines. These workflows aim to steal CI/CD credentials — critical keys for software development and deployment.",{"type":22,"tag":23,"props":37,"children":39},{"id":38},"githubs-response-approval-requirement-for-potentially-malicious-workflows",[40],{"type":28,"value":41},"GitHub's Response: Approval Requirement for Potentially Malicious Workflows",{"type":22,"tag":31,"props":43,"children":44},{},[45],{"type":28,"value":46},"In response, GitHub has implemented a security measure where potentially malicious workflows in public repositories are now held for approval before they can run. This additional human verification aims to prevent automatic execution of harmful code.",{"type":22,"tag":23,"props":48,"children":50},{"id":49},"why-this-matters",[51],{"type":28,"value":52},"Why This Matters",{"type":22,"tag":31,"props":54,"children":55},{},[56],{"type":28,"value":57},"CI/CD pipelines form the backbone of modern software delivery. Malicious workflows risk exposing sensitive credentials and facilitating broader attacks. By tightening controls around workflow execution, GitHub helps safeguard the entire software supply chain.",{"type":22,"tag":23,"props":59,"children":61},{"id":60},"moving-forward",[62],{"type":28,"value":63},"Moving Forward",{"type":22,"tag":31,"props":65,"children":66},{},[67],{"type":28,"value":68},"All developers and organizations using GitHub Actions should be aware of these changes and review their workflows carefully. Vigilance and updated security practices remain essential in the face of evolving threats.",{"title":7,"searchDepth":70,"depth":70,"links":71},2,[72,73,74,75],{"id":25,"depth":70,"text":29},{"id":38,"depth":70,"text":41},{"id":49,"depth":70,"text":52},{"id":60,"depth":70,"text":63},"markdown","content:blog:enhancing-security-github-actions-now-hold-potentially-malicious-workflows-for-approval.md","content","blog/enhancing-security-github-actions-now-hold-potentially-malicious-workflows-for-approval.md","blog/enhancing-security-github-actions-now-hold-potentially-malicious-workflows-for-approval","md",1785309524797]