The reviewdog action-setup Supply Chain Attack
Updated 5 Oct 2026 · Incident date 11 Mar 2025 · CI action
reviewdog/action-setup@v1 (tag repointed 18:42-20:31 UTC on 2025-03-11); also affected action-shellcheck, action-staticcheck, action-ast-grep, action-typos, action-composite-templateinstall.shThe GitHub Action reviewdog/action-setup@v1 was compromised on 11 March 2025 between 18:42 and 20:31 UTC. During that window the v1 tag pointed to a malicious commit. Its install.sh script dumped CI secrets into the workflow logs.
The flaw has the id CVE-2025-30154. Wiz reports that it likely led to the compromise of tj-actions/changed-files.
What happened
An attacker moved the v1 tag of reviewdog/action-setup to a malicious commit for about two hours on 11 March 2025. Any workflow that ran the action in that window executed the bad code.
Wiz reports that the payload was base64 encoded and inserted directly into install.sh. It was not fetched from a remote server. The code dumped the CI runner memory that held workflow secrets, and it wrote them to the GitHub Actions log. In public repositories anyone can read those logs.
Wiz also describes the link to the tj-actions/changed-files incident. The action tj-actions/eslint-changed-files uses reviewdog/action-setup@v1. The tj-actions/changed-files workflow ran that dependency with a personal access token, which was then stolen. CISA lists both CVE-2025-30066 for tj-actions and CVE-2025-30154 for reviewdog.
The GitHub advisory rates it high, with a CVSS score of 8.6, and the weakness class is embedded malicious code (CWE-506).
Affected versions
The affected reference is reviewdog/action-setup@v1 as it stood from 18:42 to 20:31 UTC on 11 March 2025. Other reviewdog actions that depend on it are also affected.
reviewdog/action-setupreviewdog/action-shellcheckreviewdog/action-composite-templatereviewdog/action-staticcheckreviewdog/action-ast-grepreviewdog/action-typos
The fix is in commit 3f401fe, according to the advisory. A workflow that did not run in the window did not run the bad code.
Indicators of compromise
The main sign is in the workflow log of the run.
- In the step
Run reviewdog/action-setup@v1, look for the linePreparing environment ...with a dog emoji. - Under that line, look for long strings that are base64 encoded twice. Wiz says these show the code ran and exposed secrets.
- Workflow runs between 18:42 and 20:31 UTC on 11 March 2025 that used any affected action.
How to check
Search your repositories for workflows that use the affected actions.
grep -rn "reviewdog/action-" .github/workflows
Then list the workflow runs from the window with the GitHub CLI and read their logs.
gh run list --created 2025-03-11 --limit 100
Open any run in that window and check the action-setup step for the double base64 strings.
What to do now
- Stop using the affected actions until you have updated them. Remove the references on all branches.
- Rotate every secret that a workflow run in the window could read.
- Download the workflow logs before they are deleted, so you keep the evidence.
- Update to the fixed version of
reviewdog/action-setupand pin actions to a full commit hash. - If you are in the US, you can report incidents to CISA at Report@cisa.gov.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here install.sh gained a decode-and-run step. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 77 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED install.sh It now runs a command on its own when it is installed, reads saved passwords and access keys and runs other programs. It did not before.
Frequently asked questions
What happened to reviewdog/action-setup?
On 11 March 2025 between 18:42 and 20:31 UTC the v1 tag pointed to a malicious commit whose install.sh dumped CI secrets into workflow logs. The CVE is CVE-2025-30154.
How do I check if my workflows used the compromised reviewdog action?
Search your workflows for reviewdog/action- references, then read the logs of runs from 11 March 2025 18:42 to 20:31 UTC. Look for double base64 strings in the action-setup step.
Sources
More supply chain attacks
- Trivy v0.69.4 and GitHub Actions compromise (TeamPCP) 19 Mar 2026
- tj-actions/changed-files GitHub Action compromise 14 Mar 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.