Skip to content

Security Guard

Security Guard #1837

Triggered via pull request April 2, 2026 18:58
Status Success
Total duration 7m 52s
Artifacts 6

security-guard.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

8 warnings and 1 notice
activation
File workflows/security-guard.md contains front matter which will be ignored in runtime import
agent
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Failed to process file /tmp/gh-aw/mcp-logs/rpc-messages.jsonl: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/rpc-messages.jsonl'
agent
Failed to process file /tmp/gh-aw/mcp-logs/mcp-gateway.log: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/mcp-gateway.log'
agent
GitHub MCP lockdown mode enabled for public repository. This prevents the GitHub token from accessing private repositories.
detection
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
safe_outputs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
conclusion
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
agent-artifacts
225 KB
sha256:dde0d9004fba736f143ccc39fd08507685d7d0ac96389f7d3eaf68d921c25bcd
agent-output
569 Bytes
sha256:779314692d05fb6d3d41c3f8fd8849592cc80eeb283970205f5c10bcd2bb801d
prompt Expired
6.33 KB
sha256:117b2b4f033207bea31b38d91ab7613dadc1ccd7599586e215a959d41274620e
safe-output
545 Bytes
sha256:d2ec0d57d210c14e48d8593803d6568ee8923cb54c309266866289a20b314c09
safe-output-items
162 Bytes
sha256:a5e655dc4f28644293076f84c259fb54c2a079e87e802249e7800a454eb43da9
threat-detection.log
16.8 KB
sha256:9115364e7d04615c4ff59958d361a5edf7d20478ff318c9374a80286377c3ff8