-
Notifications
You must be signed in to change notification settings - Fork 874
Closed
Labels
type/docsDocumentation creation, updates or correctionsDocumentation creation, updates or corrections
Description
Filing a public issue instead of reporting this as a private vulnerability, since this malware is a publicly known and an urgent issue.
prisma uses a compromised version of tj-actions/changed-files. The compromised action appears to leak secrets the runner has in memory.
The action is included in:
- https://github.com/prisma/docs/blob/main/.github/workflows/lost-pixel.yml
- https://github.com/prisma/docs/blob/main/.github/workflows/list-changed-pages.yml
Output of an affected run on prisma:
- https://github.com/prisma/docs/actions/runs/13866614354/job/38806902562#step:3:56;
- https://github.com/prisma/docs/actions/runs/13866700503/job/38807159456#step:4:56
From brief analysis, what was leaked looks serious. Please take immediate action.
Please review.
Learn about the compromise on StepSecurity of Semgrep.
mattlorimor
Metadata
Metadata
Assignees
Labels
type/docsDocumentation creation, updates or correctionsDocumentation creation, updates or corrections