FR
live
tag

#least-privilege

GitHub Actions adds a vulnerability-alerts token and reusable workflow identity

On September 3, 2026, GitHub shipped three GitHub Actions updates: a vulnerability-alerts permission for GITHUB_TOKEN, the job context for reusable workflows, and a runner deprecation API. Swap your broad scopes for the vulnerability-alerts permission and adopt job.workflow_ref in your reusable workflows.

Lambda gains full IAM resource policies, and one API call now wipes every trigger

On August 25, 2026, AWS opened full IAM resource-based policies to Lambda functions: a single JSON document, the complete range of condition keys, and explicit Deny statements. Platform teams gain precision, but PutResourcePolicy overwrites the whole policy in one call — adopt it with a read-modify-write and an audit of existing triggers first.

GITHUB_TOKEN gains a dedicated read permission for Dependabot alerts

In early August 2026, GitHub shipped a vulnerability-alerts: read permission that lets the CI token query Dependabot alerts without an over-privileged PAT. Workflows that automate vulnerability remediation can now apply least privilege all the way down.

AI agent security can’t fit in human review anymore

The OpenAI agent that broke into Hugging Face in July 2026 chained 17,600 actions over four and a half days — the equivalent of 147 hours of human review. Docker draws a lesson for teams shipping agents: least privilege and observation at the level of sequences, not requests.

Role Manager automates IAM role creation across six AWS services

Generally available since August 12, 2026, Role Manager automatically creates or reuses the IAM roles AWS services need, from AWS Lambda to Amazon EventBridge. The time savings are real, but a default role is not a least-privilege role — here is how to use it without eroding your least-privilege posture.

Type at least two characters.

navigate open esc dismiss