
GitHub has implemented a new security feature for its Actions platform to mitigate supply chain attacks. The platform now holds potentially malicious workflows for approval, preventing them from executing until reviewed by a collaborator with write access. This measure is automatically applied to public repositories on GitHub.com, enhancing security by requiring approval through an authenticated session. However, this protection is not yet available for GitHub Enterprise Server users.
Read original