DirectXShaderCompiler used a compromised version of tj-actions/changed-files. The compromised action appears to have leaked secrets the runner was running in memory.
The action was included in:
|
uses: tj-actions/changed-files@v41 |
Output of an affected run:
Please review.
Learn about the compromise on StepSecurity of Semgrep.
This issue has been assigned CVE-2025-30066