DevOps.com reports this information.
DevOps.com reports that GitHub has made workflow execution protections generally available for GitHub Enterprise, organizations, and repositories. An administrator builds an allowlist of actors and events, and GitHub checks the rules before a workflow run begins.
Rules can target individual workflow files instead of an entire repository. Evaluate mode shows which runs a rule would block before it is enforced.
On November 2, 2026, GitHub will begin enforcing a default rule for pull_request_target in public repositories without an event policy. The rule does not apply to private or internal repositories.
Claim check:
- GitHub can give a contributor write access without giving them the ability to execute workflows. (confirmed only by the carrying publication: evidence; «Actor rules let you separate who contributes code from who runs your CI, so you can grant a contributor write access without granting them the ability to execute workflows.»)
- GitHub has made workflow execution protections generally available for GitHub Enterprise, organizations, and repositories. (confirmed only by the carrying publication: evidence; «On September 17, the company made workflow execution protections GA for GitHub Enterprise, organizations, and repositories.»)
- An administrator builds an allowlist of actors and events, and GitHub checks the rules before a workflow run begins. (confirmed only by the carrying publication: evidence; «Administrators build an allowlist. GitHub checks the rules before a workflow run begins. If the actor or the event isn’t on the list, the run doesn’t start.»)
- Rules can target individual workflow files instead of an entire repository. (confirmed only by the carrying publication: evidence; «First, rules can now target specific workflow files instead of a whole repository.»)
- Evaluate mode shows which runs a rule would block before it is enforced. (confirmed only by the carrying publication: evidence; «Evaluate mode carries over from the preview. It lets admins “run your rules in shadow, so you can see exactly what a rule would block before you enforce it,” according to the June announcement.»)
- On November 2, 2026, GitHub will begin enforcing a default rule for pull_request_target in public repositories without an event policy. (confirmed only by the carrying publication: evidence; «A default rule disables pull_request_target in public repositories that don’t already have an event policy. It’s running in evaluate mode today. Enforcement starts November 2, 2026. It doesn’t apply to private or internal repositories.»)
- The rule does not apply to private or internal repositories. (confirmed only by the carrying publication: evidence; «It doesn’t apply to private or internal repositories.»)
Publications:
score 75.0 out of 100 · kind: announcement