GitHub Actions 2026: OIDC Claims, Runner Strategy, and Workflow Governance
How recent GitHub Actions updates change secure CI design, from OIDC custom properties to rerun limits and runner fleet planning.
Security and identity systems. Passkeys, privacy, and browser platform changes.
180 articles
How recent GitHub Actions updates change secure CI design, from OIDC custom properties to rerun limits and runner fleet planning.
A practical migration guide to OIDC-based authentication for private registries used by Dependabot and code scanning, with policy and incident-response patterns.
How to redesign CI security architecture now that Dependabot and code scanning can use OIDC with private registries at org scale.
Using GitHub secret scanning improvements and deployment context metadata to prioritize, route, and close security incidents faster.
A security architecture for moving from human-verification assumptions to policy-based agent identity and scoped authorization.
A practical architecture for giving autonomous agents scoped private access without exposing internal services to the public internet.
How to design private tool access for AI agents on Cloudflare with scoped identity, policy boundaries, and measurable blast-radius control.
A practical operating model for introducing Copilot Autopilot safely with policy tiers, audit trails, and measurable guardrails.
A practical migration playbook for enterprises moving from passwords and SMS OTP toward passkey-first, phishing-resistant identity.
A field guide to turning new Copilot residency and compliance switches into enforceable engineering workflows.
How product and platform teams should design household AI systems with strict data boundaries, observability, and graceful failure behavior.
A practical operating model for security, platform, and product teams translating post-quantum urgency into measurable migration work.
A practical operating model for introducing Cloudflare Organizations across multi-account enterprise estates.
A practical operating model for adopting Cloudflare Organizations beta with federated identity, least privilege, and migration guardrails.
How to convert post-quantum ambition into an executable migration program across TLS, internal PKI, and vendor dependencies.
How to operationalize GitHub’s new AI-agent assignment for Dependabot alerts with review gates, reproducibility, and measurable risk reduction.
A practical enterprise architecture for combining Dependabot alerts, AI-assisted remediation, and Nix ecosystem support with auditable controls.
How Cloudflare Organizations changes identity, policy, and operations for enterprises managing many Cloudflare accounts.
How to turn post-quantum urgency into an executable roadmap across TLS, service identity, and operational risk controls.
GitHub Copilot cloud agent commit signing enables stronger branch protection and clearer provenance for agent-generated changes.