> In this specific case, the bad actor changes all of the version tags to point to their malicious commit: https://github.com/tj-actions/changed-files/tags
This required compromising the entire repository, yes? It can't be explained as the maintainer being tricked into merging something malicious?