🔖(deps): Update tj-actions/changed-files digest to 0e58ed8#1111
🔖(deps): Update tj-actions/changed-files digest to 0e58ed8#1111renovate[bot] merged 1 commit intomainfrom
Conversation
|
@LogFlames already reverted or not? of not could you do it? |
|
Yes, it is handled. @LogFlames rebased the commit out of main branch. |
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…e58ed8 (#1111)" This version of `changed-files` contains [malicious code](tj-actions/changed-files@0e58ed8). Reverting as suggested [here](#1111 (review)).
…e58ed8 (#1111)" This reverts commit 964b103. This is a supply chain attack see: - https://www.endorlabs.com/learn/github-action-tj-actions-changed-files-supply-chain-attack-what-you-need-to-know - https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ - renovatebot/renovate#34829
|
FTR, revert commit is 3704f37 |
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…e58ed8 (#1111)" This version of `changed-files` contains [malicious code](tj-actions/changed-files@0e58ed8). Reverting as suggested [here](#1111 (review)).
CI is now up and running again. Seems tj-actions/changed-files had been banned/depricated/removed in some way, even the older sha which we reverted to. This lead to any action containing it could not be run in The error is very weird and non descriptive, if I removed Also, because we cannot release without using the action an interim non-release action sha had to be used where |
That's weird. It seems the restriction is project based which makes me question what projects it won't work on.
Makes sense. |
This PR contains the following updates:
9200e69->0e58ed8Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.