This action by GitHub will help prevent this type of exploit, which seems like a good thing. Folks who haven’t merged a pull request before will need approvals to trigger an action: https://github.blog/2021-04-22-github-actions-update-helping...
An this exploit still working if any of contributor create malicious update