JSTGTECH
← All posts

Tagged “supplychain”

1 post

CVE-2025-30066: The GitHub Action Tag You Trusted Lied

A compromised maintainer token let attackers rewrite tj-actions/changed-files version tags, dumping CI/CD secrets from thousands of repos into public build logs.

securitycicdsupplychaingithub