Skip to content

Security Scan

Security Scan #207

Triggered via schedule April 9, 2026 05:17
Status Failure
Total duration 3m 3s
Artifacts 5

security-scan.yml

on: schedule
cargo audit
2m 59s
cargo audit
Secret scan (gitleaks)
11s
Secret scan (gitleaks)
IaC scan (checkov)
27s
IaC scan (checkov)
Matrix: CodeQL SAST
Matrix: npm audit
Matrix: Trivy container scan
Fit to window
Zoom out
Zoom in

Annotations

22 errors and 17 warnings
npm audit (client)
Process completed with exit code 1.
npm audit (components)
Process completed with exit code 1.
npm audit (api)
The strategy configuration was canceled because "npm-audit.client" failed
npm audit (api)
The operation was canceled.
npm audit (app)
The strategy configuration was canceled because "npm-audit.client" failed
npm audit (app)
The operation was canceled.
Trivy container scan (client, client/Dockerfile, stellar-escrow-client)
Path does not exist: trivy-stellar-escrow-client.sarif
Trivy container scan (client, client/Dockerfile, stellar-escrow-client)
Process completed with exit code 1.
Trivy container scan (api, api/Dockerfile, stellar-escrow-api)
The strategy configuration was canceled because "trivy-scan.client_client_Dockerfile_" failed
Trivy container scan (api, api/Dockerfile, stellar-escrow-api)
Path does not exist: trivy-stellar-escrow-api.sarif
Trivy container scan (api, api/Dockerfile, stellar-escrow-api)
Process completed with exit code 1.
IaC scan (checkov)
CKV_AWS_354: "Ensure RDS Performance Insights are encrypted using KMS CMKs"
IaC scan (checkov)
CKV_AWS_129: "Ensure that respective logs of Amazon Relational Database Service (Amazon RDS) are enabled"
IaC scan (checkov)
CKV_AWS_354: "Ensure RDS Performance Insights are encrypted using KMS CMKs"
IaC scan (checkov)
CKV_AWS_382: "Ensure no security groups allow egress from 0.0.0.0:0 to port -1"
IaC scan (checkov)
CKV_AWS_23: "Ensure every security group and rule has a description"
IaC scan (checkov)
CKV_AWS_158: "Ensure that CloudWatch Log Group is encrypted by KMS"
IaC scan (checkov)
CKV_AWS_338: "Ensure CloudWatch log groups retains logs for at least 1 year"
IaC scan (checkov)
CKV_AWS_51: "Ensure ECR Image Tags are immutable"
IaC scan (checkov)
CKV_AWS_149: "Ensure that Secrets Manager secret is encrypted using KMS CMK"
IaC scan (checkov)
CKV_AWS_149: "Ensure that Secrets Manager secret is encrypted using KMS CMK"
cargo audit
Process completed with exit code 1.
npm audit (client)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
npm audit (components)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
npm audit (api)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
npm audit (app)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
npm audit (app)
No files were found with the provided path: app/npm-audit-app.json. No artifacts will be uploaded.
Trivy container scan (client, client/Dockerfile, stellar-escrow-client)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/upload-sarif@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Trivy container scan (client, client/Dockerfile, stellar-escrow-client)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Secret scan (gitleaks)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, gitleaks/gitleaks-action@v2. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Secret scan (gitleaks)
🛑 Leaks detected, see job summary for details
Trivy container scan (api, api/Dockerfile, stellar-escrow-api)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/upload-sarif@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Trivy container scan (api, api/Dockerfile, stellar-escrow-api)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
IaC scan (checkov)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/upload-sarif@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
IaC scan (checkov)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
CodeQL SAST (javascript-typescript)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/analyze@v3, github/codeql-action/autobuild@v3, github/codeql-action/init@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL SAST (javascript-typescript)
Failed to save: Unable to reserve cache with key codeql-trap-1-2.25.1-javascript-39a8413f190445d76ed05e1188f552144e17e42a, another job may be creating this cache.
CodeQL SAST (javascript-typescript)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
cargo audit
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
cargo-audit-report Expired
3.98 KB
sha256:c7c5feaefd37fda33575ccfae0a1a8151cf79108a3a8185ad801b54ef665bd55
gitleaks-results.sarif Expired
7.19 KB
sha256:36d2083315cc34743064ab78d5624612bc9c3fc9d19c539ba82904eb8dcd2c7d
npm-audit-api Expired
322 Bytes
sha256:8cb72ec24058c10947cf48a007d2f927593ec42ae8191e453c7888c623230a69
npm-audit-client Expired
328 Bytes
sha256:e6a0606568b56d8c711d88905e8d90439d57806be1c190af1d0dc8edb2e90aa5
npm-audit-components Expired
336 Bytes
sha256:c074eaf3f5f3baf0dbce0782adc1230e11f367e9edd9521b1ba9389615936650