Skip to content

arduino-esp32 is using a compromised tj-actions/changed-files GitHub action (CVE-2025-30066) #11127

Closed
@eslerm

Description

@eslerm

arduino-esp32 uses a compromised version of tj-actions/changed-files. The compromised action appears to leak secrets the runner has in memory.

The action is included in:

Output of an affected run:

Please review.

Learn about the compromise on StepSecurity of Semgrep.

This issue has been assigned CVE-2025-30066

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions