Skip to content

Security Scanning — Vulnerability & SBOM (Universal) + NIST RMF Gate (US_FED only) #25

Security Scanning — Vulnerability & SBOM (Universal) + NIST RMF Gate (US_FED only)

Security Scanning — Vulnerability & SBOM (Universal) + NIST RMF Gate (US_FED only) #25

Triggered via schedule July 8, 2026 03:08
Status Failure
Total duration 2m 8s
Artifacts 6

security-scan.yml

on: schedule
Python Dependency Vulnerability Scan (Universal — NIST RA-5/SI-2 reporting: US_FED only)
1m 3s
Python Dependency Vulnerability Scan (Universal — NIST RA-5/SI-2 reporting: US_FED only)
Matrix: Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only)
Dependency Lockfile Validation (Universal — NIST SI-2/CM-8 reporting: US_FED only)
30s
Dependency Lockfile Validation (Universal — NIST SI-2/CM-8 reporting: US_FED only)
OPA Rego Policy Lint and Test (Universal — NIST CM-6/SI-7 reporting: US_FED only)
5s
OPA Rego Policy Lint and Test (Universal — NIST CM-6/SI-7 reporting: US_FED only)
Secret Scanning (Gitleaks)
5s
Secret Scanning (Gitleaks)
Generate and Validate SBOM (Universal — NIST CM-8/POAM-006 reporting: US_FED only)
58s
Generate and Validate SBOM (Universal — NIST CM-8/POAM-006 reporting: US_FED only)
NIST SP 800-53 Compliance Gate (US_FED only)
0s
NIST SP 800-53 Compliance Gate (US_FED only)
Fit to window
Zoom out
Zoom in

Annotations

4 errors and 3 warnings
Secret Scanning (Gitleaks)
🛑 missing gitleaks license. Go grab one at gitleaks.io and store it as a GitHub Secret named GITLEAKS_LICENSE. For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Please verify that the necessary features are enabled: Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Please verify that the necessary features are enabled: Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Please verify that the necessary features are enabled: Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only...
Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest

Artifacts

Produced during runtime
Name Size Digest
dependency-snapshot
1014 Bytes
sha256:dea1b7a2450f5a1ffa90866a7c5e46ba79ff7dade63bfc00c8e9c3191c052998
pip-audit-results
6.95 KB
sha256:cdf2452ba2df72b49df895926e4d01044818ab4d2a04b9da8f0b5068402cbe6b
sbom-0
13.1 KB
sha256:95551af89c133f753d92c73375f80185d0d65231ecfb04fceb544da7bf672163
sbom-1
13.1 KB
sha256:444cea02734ac3fbb5f944906ec72d655a62d2801ff4d3d80681ad7de1197a76
sbom-2
13.1 KB
sha256:fd1f986e883795a44c4d0ba156168844c72563d5481c2d954c76e0883e17ecd9
sbom-b2bcadace149390b0dd3359c3e3241798f2b390f
57.9 KB
sha256:8d74700768ed4bb180dd556eea797fa6958f41aa857d8389a47c3e7b79635522