Security Scanning #128
security.yml
on: schedule
Dependency Vulnerability Scan
3s
Container Security Scan
27s
Static Application Security Testing
2m 31s
Secrets Detection
7s
Annotations
6 errors and 8 warnings
|
Dependency Vulnerability Scan
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
|
Secrets Detection
Process completed with exit code 1.
|
|
Secrets Detection
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
|
|
Container Security Scan
Process completed with exit code 1.
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
Resource not accessible by integration
|
|
Static Application Security Testing
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.20.1.
|
|
Static Application Security Testing
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Resource not accessible by integration
|
|
Static Application Security Testing
Resource not accessible by integration
|