In March 2025 an attacker compromised tj-actions/changed-files and rewrote its

release tags to point at malicious code. The injected code dumped runner memory

into workflow logs, which on a public repository means printing your secrets

where anyone can read them. Around 23,000 repositories depended on that action,

most of them through a mutable tag like @v45.