<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GITHUB_TOKEN on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/github_token/</link><description>Recent content in GITHUB_TOKEN on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Fri, 31 Jul 2026 19:30:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/github_token/index.xml" rel="self" type="application/rss+xml"/><item><title>GitHub Actions Now Holds Suspicious Workflow Runs Before They Touch Your Secrets</title><link>https://www.cloudkaramchari.com/blog/github-actions-holds-malicious-workflow-runs-for-approval/</link><pubDate>Fri, 31 Jul 2026 19:30:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/github-actions-holds-malicious-workflow-runs-for-approval/</guid><description>
&lt;h1 id="github-actions-now-holds-suspicious-workflow-runs-before-they-touch-your-secrets">GitHub Actions Now Holds Suspicious Workflow Runs Before They Touch Your Secrets&lt;/h1>
&lt;p>On July 28, 2026, GitHub started automatically holding workflow runs it identifies as potentially malicious before they execute. If a run gets flagged, it sits in a pending state until a repository collaborator with write access reviews and approves it through an authenticated web session. No settings, no opt-in, no workflow file changes — GitHub applies this to public repositories on github.com by default.&lt;/p></description></item></channel></rss>