In March 2025 an attacker compromised tj-actions/changed-files and rewrote its
release tags to point at malicious code. The injected code dumped runner memory
into workflow logs, which on a public repository means printing your secrets
where anyone can read them. Around 23,000 repositories depended on that action,
most of them through a mutable tag like @v45.






