#[[Security]]

CVE-2025-30066

#Security

changed-files action (≤ v45.0.7) が侵害されたサプライチェーン攻撃の脆弱性。全タグが malicious commit に retroactively 付け替えられ、汚染された action が GitHub Actions runner の secrets を workflow ログへ dump した (embedded malicious code)。

https://www.cve.org/CVERecord?id=CVE-2025-30066 https://nvd.nist.gov/vuln/detail/CVE-2025-30066

neighbourhood

GitHub Actions GitHub Actions tj-actions changed-files の compromise tj-actions chang… サプライチェーン攻撃 サプライチェーン攻撃 tj-actions/changed-files changed-files CVE-2025-30066

backlinks · 1

links · 3