https://seclists.org/oss-sec/2025/q1/226: tj-action/changed-files GitHub action was compromised
Published Mar 19, 2025
·Updated
Affected Software
1 affected component
tj-actions changed-files
Frequently Asked Questions
1
What is the severity of vulnerability TJ-ACTIONS-CHANGED-FILES-2025-01?
The TJ-ACTIONS-CHANGED-FILES-2025-01 vulnerability is classified as high severity due to the potential exposure of sensitive credentials.
2
How do I fix vulnerability TJ-ACTIONS-CHANGED-FILES-2025-01?
To fix the TJ-ACTIONS-CHANGED-FILES-2025-01 vulnerability, you should audit your repositories for any compromised tokens and update to the latest version of tj-actions.
3
What are the indicators of compromise for TJ-ACTIONS-CHANGED-FILES-2025-01?
Indicators of compromise for TJ-ACTIONS-CHANGED-FILES-2025-01 include unusual access patterns and unexpected changes in your repository logs.
4
How can tj-scan help with TJ-ACTIONS-CHANGED-FILES-2025-01?
The tj-scan tool can help you review your logs for leaked credentials resulting from the TJ-ACTIONS-CHANGED-FILES-2025-01 compromise.
5
When was the vulnerability TJ-ACTIONS-CHANGED-FILES-2025-01 published?
The vulnerability TJ-ACTIONS-CHANGED-FILES-2025-01 was published on March 19, 2025.