home.social

#tjactions — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tjactions, aggregated by home.social.

fetched live
  1. I wrote a script to show the exact versions of Actions used in your workflows on GitHub Actions.

    It uses the audit logs (or just a list of workflow runs, for a single repo), grabs the workflow logs, and shows which commit was downloaded for each Action.

    It’s useful in cases like the tj-actions/changed-files and reviewdog compromises.

    github.com/github/audit-action

  2. I wrote a script to show the exact versions of Actions used in your workflows on GitHub Actions.

    It uses the audit logs (or just a list of workflow runs, for a single repo), grabs the workflow logs, and shows which commit was downloaded for each Action.

    It’s useful in cases like the tj-actions/changed-files and reviewdog compromises.

    github.com/github/audit-action

    #DevSecOps #SupplyChainSecurity #Actions #CiCd #GitHub #TJActions #ReviewDog

  3. ⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
    #SoftwareSupplyChainSecurity
    #tjactions
    👇
    stepsecurity.io/blog/harden-ru

  4. ⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
    #SoftwareSupplyChainSecurity
    #tjactions
    👇
    stepsecurity.io/blog/harden-ru