GitHub Actions security enforcement went live today: actions/checkout now refuses by default to execute untrusted fork code inside privileged CI/CD workflows, closing the pwn request attack vector ...
GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.