Most warnings appear while the machine is already moving. You can notice them or miss them.
GitHub Actions now holds certain potentially malicious runs in public repositories on GitHub.com before they start. A collaborator with write access reviews the run and approves it from an authenticated web session.
The product decision I keep thinking about is the pause itself. It turns the warning into a boundary. When the risk is serious, a red banner shouldn't have to compete with a process that keeps moving.
Give the system brakes.
Optional short-video concept: A workflow reaches a red warning that folds into a locked gate. A reviewer inspects it; the gate either opens or stays shut. End card: "A warning is stronger when the system can wait."













