GitHub Action tj-actions/changed-files is compromised, https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised.
> the attackers modified the action’s code and retroactively updated multiple version tags to reference the malicious commit. The […] Action prints CI/CD secrets in GitHub Actions build logs. If the workflow logs are publicly accessible (such as in public repositories), anyone could potentially read these logs and obtain exposed secrets.