GitHub now holds certain potentially malicious GitHub Actions runs for approval in public repositories. Use this bounded review checklist before approving a held workflow.
GitHub is adding more policy control around GitHub-hosted runners, including runner groups that can direct jobs to runners meeting an organization’s requirements and the ability to disable standard hosted runners. That is useful for platform teams, but a policy setting is not the same thing as a verified security boundary. The practical question is: what