Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sage is using a compromised tj-actions/changed-files GitHub action #39715

Open
eslerm opened this issue Mar 15, 2025 · 2 comments
Open

sage is using a compromised tj-actions/changed-files GitHub action #39715

eslerm opened this issue Mar 15, 2025 · 2 comments

Comments

@eslerm
Copy link

eslerm commented Mar 15, 2025

Filing a public issue instead of reporting this as a private vulnerability, since this malware is a publicly known and an urgent issue.

sage uses a compromised version of tj-actions/changed-files. The compromised action appears to leak secrets the runner has in memory.

The action is included in:

Output of an affected runs:

Please review.

Learn about the compromise on StepSecurity of Semgrep.

@fchapoton
Copy link
Contributor

fchapoton commented Mar 17, 2025

@kwankyu @tobiasdiez : I think we need to react quickly to this.

@tobiasdiez
Copy link
Contributor

See #39722 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants