menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

2w

read

288

img
dot

Image Credit: Securityaffairs

GitHub Action tj-actions/changed-files was compromised in supply chain attack

  • The GitHub Action tj-actions/changed-files was compromised, enabling attackers to extract secrets from repositories using the CI/CD workflow.
  • Threat actors compromised the GitHub Action tj-actions/changed-files, allowing the leak of secrets from repositories using the continuous integration and continuous delivery CI/CD workflow.
  • The tj-actions/changed-files GitHub Action is used in over 23,000 repositories, automating workflows by detecting file changes in commits or pull requests.
  • GitHub promptly removed the tj-actions/changed-files Action and users are advised to update to version 46.0.1 and review workflows from March 14-15 for unexpected output in the changed-files section.

Read Full Article

like

17 Likes

For uninterrupted reading, download the app