Open
Description
iggy used a compromised version of tj-actions/changed-files. The compromised action appears to leak secrets the runner has in memory.
@BartoszCiesla thank you for removing this action! c026f4d
I am reporting that credentials were leaked previously, and you may need to address this.
Output of an affected run:
Please review.
Learn about the compromise on StepSecurity of Semgrep.
This issue has been assigned CVE-2025-30066
Metadata
Metadata
Assignees
Labels
No labels