Skip to content

[SECURITY] TODO: inspect in-repo secrets and rotate them #5040

Open
@webknjaz

Description

@webknjaz

I just learned that tj-actions/changed-files was compromised and a bunch of tags (v1 through v45.0.7) were pointing to a malicious commit around on Mar 14-15, 2025.

The current CI state points to v34:

uses: tj-actions/changed-files@v34
. This effectively means that there's a chance that some secrets leaked back in March.

Details:

@abravalheri @jaraco could you confirm which secrets exist in the repo and might need rotating?

Metadata

Metadata

Labels

Needs InvestigationIssues which are likely in scope but need investigation to figure out the causecriticalgithub_actionsPull requests that update GitHub Actions code

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions