Skip to content

fix(ci): replace tj-actions/changed-files action#3762

Closed
cratelyn wants to merge 1 commit intomainfrom
kate/replace-changed-files-action
Closed

fix(ci): replace tj-actions/changed-files action#3762
cratelyn wants to merge 1 commit intomainfrom
kate/replace-changed-files-action

Conversation

@cratelyn
Copy link
Member

this commit replaces the changed-files github action, which has since been deleted due to a supply-chain attack. for more information, see the report. the report outlines an archived mirror of the original action under "Recovery Steps". this commit replaces the deleted action with this archive.

this commit replaces the `changed-files` github action, which has since
been deleted due to a supply-chain attack. for more information, see
the [report].

the report outlines an archived mirror of the original action under
["Recovery Steps"][recovery-steps]. this commit replaces the deleted
action with this archive.

[report]: https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
[recovery-steps]: https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised#next-steps

Signed-off-by: katelyn martin <kate@buoyant.io>
@cratelyn cratelyn marked this pull request as ready for review March 16, 2025 00:33
@cratelyn cratelyn requested a review from a team as a code owner March 16, 2025 00:33
@olix0r
Copy link
Member

olix0r commented Mar 17, 2025

The maintainer has engaged and provided recommendations. It's probably better for us to stay on the original repo for the time being. We can investigate other approaches later as necessary.

@olix0r olix0r closed this Mar 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants