#tjactions — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tjactions, aggregated by home.social.
-
I wrote a script to show the exact versions of Actions used in your workflows on GitHub Actions.
It uses the audit logs (or just a list of workflow runs, for a single repo), grabs the workflow logs, and shows which commit was downloaded for each Action.
It’s useful in cases like the tj-actions/changed-files and reviewdog compromises.
https://github.com/github/audit-actions-workflow-runs
#DevSecOps #SupplyChainSecurity #Actions #CiCd #GitHub #TJActions #ReviewDog
-
I wrote a script to show the exact versions of Actions used in your workflows on GitHub Actions.
It uses the audit logs (or just a list of workflow runs, for a single repo), grabs the workflow logs, and shows which commit was downloaded for each Action.
It’s useful in cases like the tj-actions/changed-files and reviewdog compromises.
https://github.com/github/audit-actions-workflow-runs
#DevSecOps #SupplyChainSecurity #Actions #CiCd #GitHub #TJActions #ReviewDog
-
Tj-actions Supply Chain Attack Traced Back to Single GitHub Token Compromise – Source: www.infosecurity-magazine.com https://ciso2ciso.com/tj-actions-supply-chain-attack-traced-back-to-single-github-token-compromise-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Tjactions
-
Tj-actions Supply Chain Attack Traced Back to Single GitHub Token Compromise – Source: www.infosecurity-magazine.com https://ciso2ciso.com/tj-actions-supply-chain-attack-traced-back-to-single-github-token-compromise-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Tjactions
-
GitHub has removed a poisoned Action used in 23,000+ repos after it exfiltrated CI secrets, prompting concerns over supply chain security
#Cybersecurity #Microsoft #GitHub #CI_CD #DevSecOps #CyberThreats #GitHubActions #Malware #CodeSecurity #tjactions
-
GitHub has removed a poisoned Action used in 23,000+ repos after it exfiltrated CI secrets, prompting concerns over supply chain security
#Cybersecurity #Microsoft #GitHub #CI_CD #DevSecOps #CyberThreats #GitHubActions #Malware #CodeSecurity #tjactions
-
CISA Warns of Exploited GitHub Action CVE-2025-30066 – Users Urged to Patch https://thecyberexpress.com/exploited-github-action-cve-2025-30066/ #GitHubPersonalAccessTokens #tjactions/changedfiles #TheCyberExpressNews #VulnerabilityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #Vulnerability #CVE202530066 #GitHubAction #CyberNews #CISA
-
CISA Warns of Exploited GitHub Action CVE-2025-30066 – Users Urged to Patch https://thecyberexpress.com/exploited-github-action-cve-2025-30066/ #GitHubPersonalAccessTokens #tjactions/changedfiles #TheCyberExpressNews #VulnerabilityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #Vulnerability #CVE202530066 #GitHubAction #CyberNews #CISA
-
Tj-actions Supply Chain Attack Exposes 23,000 Organizations – Source: www.infosecurity-magazine.com https://ciso2ciso.com/tj-actions-supply-chain-attack-exposes-23000-organizations-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Tjactions
-
Tj-actions Supply Chain Attack Exposes 23,000 Organizations – Source: www.infosecurity-magazine.com https://ciso2ciso.com/tj-actions-supply-chain-attack-exposes-23000-organizations-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Tjactions
-
A supply chain attack on a GitHub Actions tool has put up to 23,000 organisations at risk of having credentials stolen.
https://www.computing.co.uk/news/2025/security/github-attack-threatens-23-000-organisations
#technews #infosec #tjactions #github #cybersecurity #infosec #supplychainattack
-
A supply chain attack on a GitHub Actions tool has put up to 23,000 organisations at risk of having credentials stolen.
https://www.computing.co.uk/news/2025/security/github-attack-threatens-23-000-organisations
#technews #infosec #tjactions #github #cybersecurity #infosec #supplychainattack
-
⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
#SoftwareSupplyChainSecurity
#tjactions
👇
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised -
⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
#SoftwareSupplyChainSecurity
#tjactions
👇
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised