The pin you stopped reading
In March 2025 an attacker compromised tj-actions/changed-files and rewrote its release tags to point at malicious code. The injected code dumped runner memory into workflow logs, which on a public rep
helgafinn.hashnode.dev6 min read