You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I tested pinning this to a recent sha and don't see any base64 encoded secrets in output. However I think it would probably be smart to pin indirect uses like this, since from what I can see, I don't think users can pin indirect dependencies?
Code of Conduct
I agree to follow this project's Code of Conduct
The text was updated successfully, but these errors were encountered:
wyardley
changed the title
[BUG] Affected by the security issue in changed-files
[BUG] Potentially affected by the security issue in changed-files
Mar 15, 2025
Is there an existing issue for this?
Does this issue exist in the latest version?
Describe the bug?
Since this pins to a loose of
changed-files
and not a specific sha, it may well also be affected by the issue described intj-actions/changed-files#2464 and tj-actions/changed-files#2463.
To Reproduce
What OS are you seeing the problem on?
all, ubuntu-latest or ubuntu-22.04
Expected behavior?
Relevant log output
Has all relevant logs been included?
Anything else?
I tested pinning this to a recent sha and don't see any base64 encoded secrets in output. However I think it would probably be smart to pin indirect uses like this, since from what I can see, I don't think users can pin indirect dependencies?
Code of Conduct
The text was updated successfully, but these errors were encountered: