In https://github.blog/2021-04-22-github-actions-update-helping-maintainers-combat-bad-actors/ is explained that now first time contributors need approval before the workflows are run. Also see the docs.
This mechanism also greatly reduces the threat of misuse of self hosted runners. As random folks from the Internet can no longer trigger a job to be run on our self hosted runner without approval.