Deleted Comment
We strongly advise replacing all instances of tj-actions/changed-files in your workflows with our secure alternative: https://github.com/step-security/changed-files
Thanks again for your timely detection and reporting!
Deleted Comment
1] We took the public mirror from: https://code.forgejo.org/tj-actions/changed-files/src/tag/v4...
2] Undid the malicious code change: https://code.forgejo.org/tj-actions/changed-files/commit/0e5... - You can see the change here: https://github.com/trmlabs/changed-files/commit/8567847ee196...
3] Published under a v1 tag (since we can't vet historical releases and changes and didn't want folks to get confused)
If you want to contribute or report an issue, file a GH Issue or ping us at security@trmlabs.com
Been looking for something to augment work done from pg_lakehouse!