Open
Description
I just learned that tj-actions/changed-files
was compromised and a bunch of tags (v1 through v45.0.7) were pointing to a malicious commit around on Mar 14-15, 2025.
The current CI state points to v34:
setuptools/.github/workflows/main.yml
Line 244 in 7fc3471
Details:
- https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
- Multiple tags in this action are compromised tj-actions/changed-files#2463
- https://news.ycombinator.com/item?id=43372246
- CVE-2025-30066
@abravalheri @jaraco could you confirm which secrets exist in the repo and might need rotating?