GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.