Skip to content

prisma is using a compromised tj-actions/changed-files GitHub action #6743

@eslerm

Description

@eslerm

Filing a public issue instead of reporting this as a private vulnerability, since this malware is a publicly known and an urgent issue.

prisma uses a compromised version of tj-actions/changed-files. The compromised action appears to leak secrets the runner has in memory.

The action is included in:

Output of an affected run on prisma:

From brief analysis, what was leaked looks serious. Please take immediate action.

Please review.

Learn about the compromise on StepSecurity of Semgrep.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/docsDocumentation creation, updates or corrections

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions