Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-30066] GitHub Action tj-actions/changed-files supply chain attack: everything you need to know

Summary

Everything to know about the tj-actions/changed-files supply chain attack (CVE-2025-30066): how the compromise leaked CI secrets in public repo logs, attribution clues, and mitigation guidance.
Published
Collected

original ↗

Related coverage

back