Skip to content

Security Scanning

Security Scanning #347

Triggered via schedule August 11, 2026 03:38
Status Failure
Total duration 7m 24s
Artifacts 3

security-scan.yml

on: schedule
Static Application Security Testing
2m 0s
Static Application Security Testing
Dependency Vulnerability Scan
6m 59s
Dependency Vulnerability Scan
Container Security Scan
19s
Container Security Scan
Infrastructure Security Scan
56s
Infrastructure Security Scan
Secret Scanning
14s
Secret Scanning
License Compliance Scan
1m 49s
License Compliance Scan
Security Policy Compliance
8s
Security Policy Compliance
Security Report
8s
Security Report
Fit to window
Zoom out
Zoom in

Annotations

17 errors and 14 warnings
Security Policy Compliance
Process completed with exit code 1.
Secret Scanning
Process completed with exit code 1.
Secret Scanning
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
Container Security Scan
Path does not exist: scout-results.sarif
Container Security Scan
could not authenticate: user githubactions not entitled to use Docker Scout
Container Security Scan
Input required and not supplied: sarif_file
Container Security Scan
Path does not exist: trivy-results.sarif
Container Security Scan
buildx failed with: ERROR: failed to build: failed to solve: failed to read dockerfile: open Dockerfile: no such file or directory
Infrastructure Security Scan
Path does not exist: kics-results/results.sarif
Infrastructure Security Scan
Path does not exist: checkov-results.sarif
Static Application Security Testing
Path does not exist: semgrep.sarif
Static Application Security Testing
Path does not exist: bandit-results.sarif
Static Application Security Testing
Process completed with exit code 2.
Dependency Vulnerability Scan
Path does not exist: snyk-results.sarif
Dependency Vulnerability Scan
Process completed with exit code 1.
Dependency Vulnerability Scan
Process completed with exit code 2.
Security Report
Unhandled error: HttpError: Issues has been disabled in this repository.
Security Policy Compliance
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Secret Scanning
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Container Security Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, docker/build-push-action@v5, docker/setup-buildx-action@v3, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Container Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Infrastructure Security Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Infrastructure Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Infrastructure Security Scan
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Infrastructure Security Scan
Unexpected input(s) 'output_file_path', valid inputs are ['entryPoint', 'args', 'directory', 'check', 'skip_check', 'quiet', 'api-key', 'soft_fail', 'framework', 'external_checks_dirs', 'external_checks_repos', 'output_format', 'download_external_modules', 'log_level', 'config_file', 'baseline', 'soft_fail_on', 'hard_fail_on', 'container_user']
License Compliance Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Static Application Security Testing
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Static Application Security Testing
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Dependency Vulnerability Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Dependency Vulnerability Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Security Report
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4, actions/github-script@v6, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
license-report
1.79 KB
sha256:13c4e55210c947e3a3be4867b47c8b4f646e92ed59ec0faf53eeb2ef162c87f2
security-summary
304 Bytes
sha256:345218f2f5a2346228a1f416415b7c01a1d22f3f9d118eb8336e2f007f9485c3
vulnerability-reports
3.72 KB
sha256:46a0af0c69b8708dfa9bd0a52fab90ee8e5f418e081fcabba93f07605f23d5ca