Workflow execution protections in GitHub Actions generally available
GitHub Actions now offers generally available workflow execution protections, letting enterprises define allowlists for who can trigger workflows and which events start them. New features include file‑specific rules, audit insights, and a REST API for policy‑as‑code. A default rule blocks pull_request_target in public repos, initially in evaluate mode.