What's coming to our GitHub Actions 2026 security roadmap
Blog post from GitHub
Software supply chain attacks are increasing, with recent incidents targeting CI/CD automation rather than just the software, prompting GitHub to develop a 2026 roadmap for securing GitHub Actions. This roadmap aims to address vulnerabilities by enhancing security across three layers: the ecosystem, attack surface, and infrastructure. Key initiatives include introducing workflow-level dependency locking for deterministic runs and auditability, implementing policy-driven execution to reduce attack surfaces, and introducing scoped secrets for better credential management. Additionally, GitHub plans to enhance endpoint monitoring and control for CI/CD infrastructure through the Actions Data Stream for real-time execution telemetry and a native egress firewall for network traffic control. These measures are designed to make secure behavior the default, improving the verifiability and security of automation in GitHub Actions.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 18 | 1,946 | 398 | 127 | +28% |
| Observability | 3 | 4,660 | 984 | 209 | +14% |
| Real-time | 3 | 13,979 | 3,441 | 296 | +113% |
| AI Coding Assistant | 1 | 1,565 | 481 | 159 | +31% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.