Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident

by cube00on 4/5/2025, 8:10 PMwith 2 comments

by gnabgibon 4/5/2025, 8:13 PM

The Update: April 2, 2025 https://unit42.paloaltonetworks.com/github-actions-supply-ch... section is interesting (the plot thickens)

by cube00on 4/5/2025, 8:34 PM

I'm so glad someone dug into this properly after the tj-actions maintainer started locking threads and refusing to look into how the PAT was leaked.

https://github.com/tj-actions/changed-files/issues/2464#issu...