Skip to content

Commit 01e2ca8

Browse files
authored
Pin hash to a previous version in order to avoid the exploit (#3374)
This uses another version (v44) where I could find the hash (we currently used v45). In summary, the repo got compromised and all the tags versions point to a malicius commit that includes a function to expose the secrets on the github action logs, so people can fetch them.
1 parent 95cd34a commit 01e2ca8

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

.github/workflows/main.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
- name: Obtiene la lista de archivos .po con cambios (sólo en PRs)
5353
if: github.event_name == 'pull_request'
5454
id: changed-po-files
55-
uses: tj-actions/changed-files@v45
55+
uses: tj-actions/changed-files@9200e69727eb73eb060652b19946b8a2fdfb654b
5656
with:
5757
files: |
5858
**/*.po

.github/workflows/pr-comment.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
python -m pip install -r base-branch/requirements-own.txt
3838
- name: Obtiene lista de archivos con cambios
3939
id: changed-files
40-
uses: tj-actions/changed-files@v45
40+
uses: tj-actions/changed-files@9200e69727eb73eb060652b19946b8a2fdfb654b
4141
with:
4242
files: |
4343
**/*.po

0 commit comments

Comments
 (0)