Skip to content

Security Scanning

Security Scanning #418

Triggered via schedule August 25, 2026 02:53
Status Success
Total duration 7m 39s
Artifacts 5

security-scan.yml

on: schedule
Static Application Security Testing
2m 8s
Static Application Security Testing
Dependency Vulnerability Scan
6m 38s
Dependency Vulnerability Scan
Container Security Scan
2m 44s
Container Security Scan
Infrastructure Security Scan
40s
Infrastructure Security Scan
Secret Scanning
27s
Secret Scanning
License Compliance Scan
1m 44s
License Compliance Scan
Security Policy Compliance
9s
Security Policy Compliance
Security Report
55s
Security Report
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 13 warnings
Security Policy Compliance
Process completed with exit code 1.
Secret Scanning
Process completed with exit code 2.
Secret Scanning
Process completed with exit code 1.
Secret Scanning
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
Static Application Security Testing
Path does not exist: bandit-results.sarif
Static Application Security Testing
Process completed with exit code 2.
Dependency Vulnerability Scan
Path does not exist: snyk-results.sarif
Dependency Vulnerability Scan
Process completed with exit code 1.
Dependency Vulnerability Scan
Process completed with exit code 2.
Security Report
Unable to download artifact(s): Unable to download and extract artifact: Artifact download failed after 5 retries.
Security Policy Compliance
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Secret Scanning
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, gitleaks/gitleaks-action@dcedce43c6f43de0b836d1fe38946645c9c638dc. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Secret Scanning
🛑 Leaks detected, see job summary for details
Infrastructure Security Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Infrastructure Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
License Compliance Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Static Application Security Testing
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Static Application Security Testing
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Container Security Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f, github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Container Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Dependency Vulnerability Scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@11d5960a326750d5838078e36cf38b85af677262, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Dependency Vulnerability Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Security Report
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
gitleaks-results.sarif
17.1 KB
sha256:278c450962c738371bf0f4066a85967b6a75f0b97a2d3967c8b5b0f8e1f3fd3f
license-report
1.8 KB
sha256:8072b91d167701e14753698e8afe229ff89ede02b67366f1b5d72fdd3994c2af
security-summary
297 Bytes
sha256:f2303a3bdf8666482ec6ed7a1b55c094ddaf9a0424ec2a8aebb0329a14b66271
usagi-epta~wifi-densepose~N703Y7.dockerbuild
47.4 KB
sha256:86712ee6ad54b906abf6f921f487b1b6edb12f4254d158a3a48189d2c89960e5
vulnerability-reports
3.73 KB
sha256:f418917563cd30c10b4e4419d9de53ebc937040f3f808f35734cd271e2415286