I have a feeling CVE-2025-30066 could have been prevented if the "tj-actions/changed-files" had the repository tag protection setting and the stolen PAT wasn't overprivileged.
I made a thing... or two. GitHub Actions permissions Monitor and Advisor: #GitHubActions #security