FR
live
tag

#github-actions

GitHub Actions adds a vulnerability-alerts token and reusable workflow identity

On September 3, 2026, GitHub shipped three GitHub Actions updates: a vulnerability-alerts permission for GITHUB_TOKEN, the job context for reusable workflows, and a runner deprecation API. Swap your broad scopes for the vulnerability-alerts permission and adopt job.workflow_ref in your reusable workflows.

GITHUB_TOKEN gains a dedicated read permission for Dependabot alerts

In early August 2026, GitHub shipped a vulnerability-alerts: read permission that lets the CI token query Dependabot alerts without an over-privileged PAT. Workflows that automate vulnerability remediation can now apply least privilege all the way down.

GitHub Actions Hands You the Runner Keys — You Do the Driving

Custom runner images hit general availability on March 26, 2026 after a six-month public preview. They eliminate per-job setup and speed up pipelines — but shift image maintenance, security patching, and versioning squarely onto your team.

Type at least two characters.

navigate open esc dismiss