News Score: Score the News, Sort the News, Rewrite the Headlines

Semgrep | 🚨 Popular GitHub Action tj-actions/changed-files is compromised

Popular GitHub Action tj-actions/changed-files has been compromised (GitHub issue) with a payload that appears to attempt to dump secrets, impacting thousands of CI pipelines. This isn’t the first security issue with tj-actions/changed-files—see prior vulnerability CVE-2023-51664.What you should doFind out where you're affectedThe simplest way to find this is to grep for tj-actions in your codebase.If you're on GitHub, look at the results of this query, replacing YOURORG with your organization's...

Read more at semgrep.dev

© News Score  score the news, sort the news, rewrite the headlines