Skip to content

DirectXShaderCompiler used a compromised tj-actions/changed-files GitHub action (CVE-2025-30066) #7213

@eslerm

Description

@eslerm

DirectXShaderCompiler used a compromised version of tj-actions/changed-files. The compromised action appears to have leaked secrets the runner was running in memory.

The action was included in:

Output of an affected run:

Please review.

Learn about the compromise on StepSecurity of Semgrep.

This issue has been assigned CVE-2025-30066

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions