- Sources: GitHub blog, HN 49096427
- Summary: GitHub published a post on 2026-07-28 summarising changes to npm and GitHub Actions aimed at steps that recur across supply chain attack chains, describing work shipped over the past few months. Four of the changes are live and dated to June 2026 in the post, and they alter defaults rather than adding opt-in features. High-impact npm accounts go read-only for 72 hours after an email change or a 2FA recovery.
actions/checkout no longer checks out fork code under commonly exploited triggers unless a workflow opts out. Workflow trigger types and triggering identities can be restricted by policy. Untrusted workflows can no longer write to the Actions cache shared with privileged ones. - Why it matters: These are default changes that landed in June 2026, so a workflow that relied on fork checkout under those triggers, or on a cache shared with privileged jobs, is already exposed to breaking with no change on the repository side.
send feedback on this story