tj-actions/changed-files github actions compromised #1684
prabhu
announced in
Announcements
Replies: 1 comment
-
Looks like there is a new CVE against GitHub/CodeQL-action. Hope folks have started collecting GitHub components by now. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
tj-actions/changed-files#2463
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
The good news is that our projects do not use this step. Even better, cdxgen collects GitHub actions by default.
However, cdxgen does not collect GitHub Actions in the following two scenarios (which could represent the bulk of use cases):
-t java
instead of-t universal
).--exclude-type github
).Ideally, users must let the sbom tools to detect all languages and generate a comprehensive SBOM. Please comment if your team has successfully collected GitHub Actions with Dependency Track and managed to patch the affected applications that used these compromised actions.
Beta Was this translation helpful? Give feedback.
All reactions