Skip to content
This repository was archived by the owner on Jun 21, 2025. It is now read-only.
This repository was archived by the owner on Jun 21, 2025. It is now read-only.

SwitchMap Docs - Urgent Security Bug: tj-actions GitHub Action is compromised #27

@palisadoes

Description

@palisadoes

Describe the bug

  1. The tj-actions GitHub Action is compromised and the GitHub action repository has been deleted.
  2. This is causing many of our GitHub actions to fail

Advisory notifications:

  1. GHSA-mcph-m25j-8j63
  2. https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
  3. https://news.ycombinator.com/item?id=43367987
  4. https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
  5. https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066l

Expected Outcome

  1. Find a reliable alternative to tj-actions which reference steps.changed-files and steps.changed_files in the GitHub action files
  2. Update the GitHub action files to use the new methodology
  3. No functionality of the GitHub actions must be altered

Reference PRs

  1. Fix tj-actions GitHub Action is compromised (Fixes #3367) talawa-api#3369

Reference Issues

  1. API - Urgent Security Bug: tj-actions GitHub Action is compromised talawa-api#3367
  2. Admin - Urgent Security Bug: tj-actions GitHub Action is compromised talawa-admin#3851
  3. Mobile - Urgent Security Bug: tj-actions GitHub Action is compromised talawa#2783
  4. Talawa Docs - Urgent Security Bug: tj-actions GitHub Action is compromised talawa-docs#981
  5. SwitchMap - Urgent Security Bug: tj-actions GitHub Action is compromised switchmap-ng#303
  6. SwitchMap Docs - Urgent Security Bug: tj-actions GitHub Action is compromised #27

Potential internship candidates

Please read this if you are planning to apply for a Palisadoes Foundation internship

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingsecurity

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions