Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-30066] Get the TL;DR: tj-actions/changed-files Supply Chain Attack

Summary

The tj-actions/changed-files GitHub Action, which is currently used in over 23,000 repositories, has been compromised, leaking secrets through workflow logs and impacting thousands of CI pipelines.
Published
Collected

original ↗

Related coverage

back