Content by Greg Ose (2)
Greg Ose summarizes the security changes GitHub and npm shipped over recent months to break common supply chain attack paths, focusing on preventing workflow compromise, reducing credential exposure, slowing malicious propagation, and improving incident response options for enterprises.
Greg Ose outlines GitHub Actions’ 2026 security roadmap, covering dependency locking for reproducible workflows, centralized policy controls for workflow execution and secrets, plus new runner telemetry and egress controls to reduce CI/CD supply chain risk.
End of content