-
Notifications
You must be signed in to change notification settings - Fork 397
Closed
Labels
bugSomething isn't workingSomething isn't working
Description
Recently, several of tj-actions
GitHub Actions have been compromised with vulnerabilities, including tj-actions/verify-changed-files
used by this template:
uses: tj-actions/verify-changed-files@v18 |
uses: tj-actions/verify-changed-files@v18 |
https://github.com/airvitap/airvitap.github.io/actions/runs/13873209466/job/38822331341
References
- https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
- https://nvd.nist.gov/vuln/detail/CVE-2023-52137
- https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
- https://news.ycombinator.com/item?id=43367987
- GHSA-ghm2-rq8q-wrhc
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working