Semgrep | 🚨 Popular GitHub Action tj-actions/changed-files is compromised
Popular GitHub Action tj-actions/changed-files has been compromised (GitHub issue) with a payload that appears to attempt to dump secrets, impacting thousands of CI pipelines. This isn’t the first security issue with tj-actions/changed-files—see prior vulnerability CVE-2023-51664.What you should doFind out where you're affectedThe simplest way to find this is to grep for tj-actions in your codebase.If you're on GitHub, look at the results of this query, replacing YOURORG with your organization's...
Read more at semgrep.dev