Skip to content

Security Scanning

Security Scanning #128

Triggered via schedule October 22, 2025 03:04
Status Failure
Total duration 2m 41s
Artifacts

security.yml

on: schedule
Dependency Vulnerability Scan
3s
Dependency Vulnerability Scan
Container Security Scan
27s
Container Security Scan
Static Application Security Testing
2m 31s
Static Application Security Testing
Secrets Detection
7s
Secrets Detection
Fit to window
Zoom out
Zoom in

Annotations

6 errors and 8 warnings
Dependency Vulnerability Scan
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
Secrets Detection
Process completed with exit code 1.
Secrets Detection
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
Container Security Scan
Process completed with exit code 1.
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
Resource not accessible by integration
Static Application Security Testing
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.20.1.
Static Application Security Testing
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Resource not accessible by integration
Static Application Security Testing
Resource not accessible by integration