tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066
https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
https://www.securityweek.com/impact-root-cause-of-github-actions-supply-chain-hack-revealed/
https://thehackernews.com/2025/03/cisa-warns-of-active-exploitation-in.html
https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463
https://github.com/tj-actions/changed-files/issues/2477
https://github.com/tj-actions/changed-files/issues/2464
https://github.com/tj-actions/changed-files/issues/2463
https://github.com/rackerlabs/genestack/pull/903
https://github.com/modal-labs/modal-examples/issues/1100
https://github.com/espressif/arduino-esp32/issues/11127