Skip to content

hotfix: pin tj-actions/changed-files by SHA #19847

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

Claire-Thib
Copy link

@Claire-Thib Claire-Thib commented Mar 15, 2025

What does this PR do?

This PR pins the tj-actions/changed-files GitHub action to a SHA corresponding to a version that is not compromised. For details on the compromise, see:

https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
Compromised versions leak CI secrets, so this repo's CI secrets will need to be rotated.

Motivation

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@Claire-Thib Claire-Thib requested a review from a team as a code owner March 15, 2025 07:48
@Claire-Thib Claire-Thib requested a review from goxberry March 15, 2025 07:48
@Claire-Thib Claire-Thib changed the title Pinning the tj-actions/changed-file incident-36213 hotfix: pin tj-actions/changed-files by SHA Mar 15, 2025
@ofek
Copy link
Contributor

ofek commented Mar 15, 2025

That repo no longer exists, we should favor this manual implementation #19848

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants