Understanding and Re-Creating the tj-actions/changed-files Supply Chain AttackAnother reason runtime security is so important, and patching ain't what it seems Update 3: Wiz research has published that the initial leak was actually due to an upstream workflow, reviewdog/actions-setup@v1. This attack was done with a local script instead of calling out to gist, but similarly printed tokens in job lo

