πŸ”’πŸ’° A crucial GitHub action got compromised, but hey, let's not panicβ€”our CEO's vision and a $100M funding round will magically fix everything! Nothing screams "We care about security" louder than a sales pitch for #AI #triage and semantic analysis. πŸ™„βœ¨
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ #GitHubCompromise #SecurityFunding #TechNews #HackerNews #ngated
Semgrep | 🚨 Popular GitHub Action tj-actions/changed-files is compromised

Popular GitHub Action tj-actions/changed-files has been compromised with a payload that appears to attempt to dump secrets, impacting thousands of CI pipelines.

Semgrep