Skip to content
This repository was archived by the owner on Aug 7, 2025. It is now read-only.

Conversation

zxiiro
Copy link
Contributor

@zxiiro zxiiro commented Mar 15, 2025

The tags in tj-actions/changed-files action are compromised and are leaking GitHub secrets in repos using the compromised repo. This pins the action to a known good hash.

https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised

The tags in tj-actions/changed-files action are compromised and are
leaking GitHub secrets in repos using the compromised repo. This pins
the action to a known good hash.

https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised

Signed-off-by: Thanh Ha <thanh.ha@linuxfoundation.org>
@seemethere seemethere merged commit 4f2b031 into pytorch:master Mar 15, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants