Popular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secrets
Popular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secrets

semgrep.dev
Semgrep | 🚨 Popular GitHub Action tj-actions/changed-files is compromised

Here's a good reason why you should pin to specific sha hashes, not just release versions.