-
Notifications
You must be signed in to change notification settings - Fork 395
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GitHub Action tj-actions/changed-files is compromised #3373
Comments
Edit: The https://github.com/tj-actions/changed-files repo has now been deleted. |
Hi @hugovk, is this still relevant?
Per https://github.com/tj-actions/changed-files/releases/tag/v46, we should revoke the tokens and maybe use new tagged versions. |
It must have been temporarily made private, and made public again after they removed the malicious commits. The advice at https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/#header-3 is:
|
Per discussion in issue #3373, this PR update `tj-actions/changed-files` to its latest version [v46](https://github.com/tj-actions/changed-files/releases/tag/v46.0.3). Related PR: #3374 Supersedes #3377
See https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
https://github.com/search?q=org%3Apython+tj-actions&type=code
https://github.com/Ana06/get-changed-files could be used as a replacement, or you could rewrite the logic in a Python script.
The text was updated successfully, but these errors were encountered: