What's coming to our GitHub Actions 2026 security roadmap
… Instead of reasoning about security across individual YAML files, you define central policies that control: Who can trigger workflows Which events are allowed This shifts the model from distributed, per-workflow configuration that’s difficult to audit and easy to misconfigure, to centralized policy… …