VYPR

GitHub Actions package

tj-actions/verify-changed-files

pkg:github/tj-actions/verify-changed-files

Vulnerabilities (1)

  • CVE-2023-52137Dec 29, 2023
    affected < 17fixed 17

    The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-ac