“GitHub has told me that they don’t consider this a security issue (I disagree), so I’m publishing this post as-is.”

GitHub Actions policies let an org block specific actions. Clone the blocked action onto the runner and run it from a local path, and the policy never checks. GitHub said it is not a security issue and quietly updated the docs. A control that looks like a boundary and is not one is worse than no control.