What's coming to our GitHub Actions 2026 security roadmap
… When a dependency is compromised, the change can propagate immediately across every workflow that references it. As recent supply chain incidents have shown, we can’t rely on the security posture of every maintainer and repository in the ecosystem to prevent the introduction of malicious code. …