# GitHub Actions policy now supports blocking and SHA pinning actions

DevFeed: [GitHub Actions policy now supports blocking and SHA pinning actions](<https://devfeed.tech/articles/github-actions-policy-now-supports-blocking-and-sha-pinning-actions-72387.md>)

Original publisher: [Read original article](<https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions>)

Author: Allison

Published: 2025-08-15T15:05:08Z

Content type: release

Language: en

Sources: [GitHub Changelog](<https://devfeed.tech/sources/github-changelog.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [asyncapi supply chain attack](<https://devfeed.tech/topics/asyncapi-supply-chain-attack.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

GitHub Actions policies now support explicitly blocking actions and reusable workflows, and administrators can require workflows to pin actions to full commit SHAs. These controls help limit exposure to compromised dependencies. The release also describes immutable releases, attestations, and protections intended to strengthen artifact integrity and supply chain security.

## Source excerpt

GitHub Actions is powered by a diverse ecosystem of first-party and community contributed actions. If one of these actions has a vulnerability or is compromised by a malicious actor, it...