Skip to content

Security Guard

Security Guard #1652

Triggered via pull request March 19, 2026 19:04
Status Success
Total duration 7m 16s
Artifacts 6

security-guard.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

8 warnings and 1 notice
activation
File workflows/security-guard.md contains front matter which will be ignored in runtime import
agent
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Failed to process file /tmp/gh-aw/mcp-logs/rpc-messages.jsonl: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/rpc-messages.jsonl'
agent
Failed to process file /tmp/gh-aw/mcp-logs/mcp-gateway.log: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/mcp-gateway.log'
agent
GitHub MCP lockdown mode enabled for public repository. This prevents the GitHub token from accessing private repositories.
detection
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
safe_outputs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
conclusion
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
agent-artifacts
162 KB
sha256:64a1628840ad6eac0e8bc8f22f53ef98fd1ba083d2b52244ffb8da9d807c79ab
agent-output
605 Bytes
sha256:a85743b4be6f70f55be4d9b999300deec0285490ece5ac1888f094f77597673e
prompt Expired
6.33 KB
sha256:fb1306cc1ec65933bffe116bf40d288942d1fe32053c9d9d22ea9b8c5ae7f551
safe-output
580 Bytes
sha256:3a2c5fb95d30000563788bb6a0ca6782f29abb42df0ebc187395e7c71ea0c406
safe-output-items
162 Bytes
sha256:d75d0a80dac7b7fb60e1105ad5a846c07e2dc11ecd76dd61ea9d43a134246de8
threat-detection.log
16.5 KB
sha256:f6cd18d847efc6818a4d3935aa1b160f2013a4e8f45b64c262219f4b7837f816