GitHub Actions Supply Chain Attack
ID: 931611a7-e073-5bb6-a26c-b497f36cd5dc
STIX ID: report--931611a7-e073-5bb6-a26c-b497f36cd5dc
Feed Name: FortiGuard Threat Signals
A supply-chain compromise impacting popular GitHub Actions (tj-actions/changed-files and reviewdog/action-setup) was disclosed; both issues were assigned CVEs (CVE-2025-30066 and CVE-2025-30154) and added to CISA’s Known Exploited Vulnerabilities catalog. The compromise potentially exposed workflow secrets — including access keys, GitHub PATs, npm tokens, and private RSA keys — across thousands of repositories (the changed-files action is used by over 23,000 repos). The investigation is ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
