The change signals the beginning of a new ‘secure by default’ era in which security will be defined by the GitHub system rather than being left to discretion of developers. As part of that effort, on ...
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review approvals, permissions, and risks.