Dev.to
techCenter
The pin you stopped readingtranslating…
In March 2025 an attacker compromised tj-actions/changed-files and rewrote its
release tags to point at malicious code. The injected code dumped runner memory
into workflow logs, which on a public repository means printing your secrets
where anyone can read them. Around 23,000…
Keywords#code#read#tech
Comments
Sign in to join the discussion.
Loading comments…