-
Notifications
You must be signed in to change notification settings - Fork 288
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Enhancement] Remove tj-actions/changed-files from the workflows #5400
Labels
enhancement
New Enhancement
Comments
Seem like it is just changing tags to point to this commit tj-actions/changed-files@0e58ed8. And since we already lock to a commit a while ago I think we are fine for now. Thanks. |
Seems resolved: tj-actions/changed-files#2464 (comment) |
@Divyaasm Can you please take care of upgrading to recent/fixed version accordingly? |
Thank you! Assigning it to you. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Apparently tj-actions/changed-files has been compromised:
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
opensearch-project/OpenSearch#17597
I realized that in our repo has set this to a specific commit, so no issues for us now.#5129Based on the original report very likely we are also affected:
Most versions of tj-actions/changed-files are compromised.
However, we do need to think about moving it out.
Thanks.
The text was updated successfully, but these errors were encountered: