Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(security) tj-actions compromised #3208

Closed
davidweterings opened this issue Mar 15, 2025 · 1 comment · Fixed by #3209
Closed

(security) tj-actions compromised #3208

davidweterings opened this issue Mar 15, 2025 · 1 comment · Fixed by #3209
Assignees

Comments

@davidweterings
Copy link

davidweterings commented Mar 15, 2025

Had to check this at work and had a local fork of go-feature-flag

https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/

https://github.com/search?q=repo%3Athomaspoignant%2Fgo-feature-flag%20tj-actions&type=code

@thomaspoignant thomaspoignant changed the title tj-actions compromised (security) tj-actions compromised Mar 15, 2025
@thomaspoignant
Copy link
Owner

thomaspoignant commented Mar 15, 2025

Hey, thanks for raising this.
As an immediate action I have rotated all the secrets, and I am about to open a PR to remove the usage of tj-actions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants