logo

GitHub Actions Supply Chain Attack

ID: 931611a7-e073-5bb6-a26c-b497f36cd5dc

STIX ID: report--931611a7-e073-5bb6-a26c-b497f36cd5dc

Feed Name: FortiGuard Threat Signals

Threat Score
85/100

Date Published: 2025-03-26

Date Updated: 2026-07-28

...
...

A supply-chain compromise impacting popular GitHub Actions (tj-actions/changed-files and reviewdog/action-setup) was disclosed; both issues were assigned CVEs (CVE-2025-30066 and CVE-2025-30154) and added to CISA’s Known Exploited Vulnerabilities catalog. The compromise potentially exposed workflow secrets — including access keys, GitHub PATs, npm tokens, and private RSA keys — across thousands of repositories (the changed-files action is used by over 23,000 repos). The investigation is ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.