New GitHub Action supply chain attack: reviewdog/action-setup A supply chain attack on tj-actions/changed-files caused many repositories to leak their secrets over the weekend. Wiz Research has discovered an additional supply chain attack on reviewdog/actions-setup@v1, that may have contributed to the compromise of tj-actions/changed-files. March 19, 2025 update: This issue has been assigned CVE-2