GitHub now holds certain potentially malicious GitHub Actions runs for approval in public repositories. Use this bounded review checklist before approving a held workflow.
GitHub has added a shorter way to reference an action or reusable workflow that lives in the same repository. The new self-repository syntax starts a uses: value with $/, and GitHub says it is available on github.com when the Actions runner is version 2.336.0 or newer. This is a small workflow change with a useful
GitHub is adding more policy control around GitHub-hosted runners, including runner groups that can direct jobs to runners meeting an organization’s requirements and the ability to disable standard hosted runners. That is useful for platform teams, but a policy setting is not the same thing as a verified security boundary. The practical question is: what