Drooid Logo
Back to today’s briefing

Story perspectives

GitHub Supply Chain Attack Exposes Secrets in 23,000 Repositories

3/17/2025

50 6

1 of 2

GitHub Responds to Attack
  • A recent supply chain attack targeted the tj-actions/changed-files GitHub Action, impacting over 23,000 repositories. This breach allowed malicious code to expose CI/CD secrets in build logs, endangering sensitive data. GitHub has swiftly reversed the changes and urged users to update their workflows and change any compromised secrets, underscoring the critical vulnerabilities in open-source software.
1 / 2