Whats coming to our GitHub Actions 2026 security roadmap
Summary
GitHub published a 2026 security roadmap for GitHub Actions that focuses on making CI/CD secure-by-default across dependency management, execution policy, and endpoint controls. It will introduce a dependencies lock file to pin direct and transitive Action commits, centralized policy-driven execution and scoped secrets to reduce over-permissioning, and enterprise telemetry via an Actions Data Stream plus a native egress firewall for GitHub-hosted runners. The roadmap includes safe rollout features such as evaluate mode, milestones toward immutable releases and hardened publishing, and role changes for secret management to enforce least privilege. These changes target software supply-chain attacks and aim to give enterprises enforceable trust boundaries and better observability without requiring teams to rebuild their CI/CD workflows.