-
-
Notifications
You must be signed in to change notification settings - Fork 299
Closed
Description
Example this tag was just updated 3 hours back and is potentially exfiltrating credentials
https://github.com/tj-actions/changed-files/tags?after=v35.9.3
You can read more here: https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
Reported the issue via the email address provided in the security.md
file and also reported it via private vulnerability disclosure to generate a CVE.
ElijahLynn, mattmoor, mdelapenya, reedloden, ashishkurmi and 72 moreeslerm, mattmoor, ashishkurmi, cyb3rjerry, mattlorimor and 27 moreQubitium, felickz, farkmarnum, wyardley, transitive-bullshit and 12 more
Metadata
Metadata
Assignees
Labels
No labels