GitHub now holds certain potentially malicious GitHub Actions runs for approval in public repositories. Use this bounded review checklist before approving a held workflow.
GitHub has added a shorter way to reference an action or reusable workflow that lives in the same repository. The new self-repository syntax starts a uses: value with $/, and GitHub says it is available on github.com when the Actions runner is version 2.336.0 or newer. This is a small workflow change with a useful
When your AI coding assistant pulls in a package, who checks whether that package is safe? Most teams assume their existing dependency scanner catches the risk. The reality is more complicated — and more dangerous — than a single scan can address. If you use GitHub Copilot, Cursor, Claude Code, or any AI coding agent,