Skip to content

Conversation

@cosmos-renovate-bot
Copy link
Contributor

@cosmos-renovate-bot cosmos-renovate-bot bot commented Mar 17, 2025

This PR contains the following updates:

Package Type Update Change
tj-actions/changed-files action major v45 -> v46

Release Notes

tj-actions/changed-files (tj-actions/changed-files)

v46

Compare Source

Changes in v46.0.5

What's Changed

Full Changelog: tj-actions/changed-files@v46...v46.0.5


Changes in v46.0.4

What's Changed

Full Changelog: tj-actions/changed-files@v46...v46.0.4


Changes in v46.0.3

What's Changed

Full Changelog: tj-actions/changed-files@v46...v46.0.3


Changes in v46.0.2

What's Changed

New Contributors

Full Changelog: tj-actions/changed-files@v46...v46.0.2


Changes in v46.0.1

[!WARNING]
Security Alert: A critical security issue was identified in this action due to a compromised commit.

This commit has been removed from all tags and branches, and necessary measures have been implemented to prevent similar issues in the future.

Action Required:

  • Review your workflows executed between March 14 and March 15. If you notice unexpected output under the changed-files section, decode it using the following command: echo 'xxx' | base64 -d | base64 -d
    If the output contains sensitive information (e.g., tokens or secrets), revoke and rotate those secrets immediately.
  • If your workflows reference this commit directly by its SHA, you must update them immediately to avoid using the compromised version.
  • If you are using tagged versions (e.g., v35, v44.5.1), no action is required as these tags have been updated and are now safe to use.

Additionally, as a precaution, we recommend rotating any secrets that may have been exposed during this timeframe to ensure the continued security of your workflows.

What's Changed

Full Changelog: tj-actions/changed-files@v46...v46.0.1


Changes in v46.0.0

[!WARNING]
Security Alert: A critical security issue was identified in this action due to a compromised commit.

This commit has been removed from all tags and branches, and necessary measures have been implemented to prevent similar issues in the future.

Action Required:

  • Review your workflows executed between March 14 and March 15. If you notice unexpected output under the changed-files section, decode it using the following command: echo 'xxx' | base64 -d | base64 -d
    If the output contains sensitive information (e.g., tokens or secrets), revoke and rotate those secrets immediately.
  • If your workflows reference this commit directly by its SHA, you must update them immediately to avoid using the compromised version.
  • If you are using tagged versions (e.g., v35, v44.5.1), no action is required as these tags have been updated and are now safe to use.

Additionally, as a precaution, we recommend rotating any secrets that may have been exposed during this timeframe to ensure the continued security of your workflows.

What's Changed

New Contributors

Full Changelog: tj-actions/changed-files@v45.0.5...v46.0.0

What's Changed

Full Changelog: tj-actions/changed-files@v45.0.5...v46.0.0



Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@cosmos-renovate-bot cosmos-renovate-bot bot force-pushed the renovate/tj-actions-changed-files-46.x branch 2 times, most recently from 4b305c8 to 28871bf Compare March 24, 2025 03:07
@cosmos-renovate-bot cosmos-renovate-bot bot force-pushed the renovate/tj-actions-changed-files-46.x branch from 28871bf to a4f29a2 Compare April 5, 2025 03:04
@cosmos-renovate-bot cosmos-renovate-bot bot force-pushed the renovate/tj-actions-changed-files-46.x branch from a4f29a2 to a00de07 Compare April 10, 2025 03:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

1 participant