Security Analysis #272
security.yaml
on: schedule
Dependency Vulnerability Scan
1m 6s
Secrets Detection
8s
Matrix: CodeQL Analysis
Annotations
3 errors and 13 warnings
|
Dependency Vulnerability Scan
Process completed with exit code 1.
|
|
CodeQL Analysis (javascript)
Maximum retry attempts exhausted (4), aborting database upload
|
|
CodeQL Analysis (typescript)
Maximum retry attempts exhausted (4), aborting database upload
|
|
Secrets Detection
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809, actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Dependency Vulnerability Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4, pnpm/action-setup@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Dependency Vulnerability Scan
No files were found with the provided path: sbom.spdx.json
**/sbom.spdx.json. No artifacts will be uploaded.
|
|
CodeQL Analysis (javascript)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4, github/codeql-action/analyze@v3, github/codeql-action/autobuild@v3, github/codeql-action/init@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
CodeQL Analysis (javascript)
Failed to save: Unable to reserve cache with key codeql-trap-1-2.25.1-javascript-2e254ac19a696394030601bc602f54945b12bfc4, another job may be creating this cache.
|
|
CodeQL Analysis (javascript)
Failed to upload database for javascript: Resource not accessible by integration - https://docs.github.com/rest
|
|
CodeQL Analysis (javascript)
1 issue was detected with this workflow: CodeQL language 'javascript' is referenced by more than one entry in the 'language' matrix parameter for job 'codeql'. This may result in duplicate alerts. Please edit the 'language' matrix parameter to keep only one of the following: 'javascript', 'typescript'.
|
|
CodeQL Analysis (javascript)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
CodeQL Analysis (typescript)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4, github/codeql-action/analyze@v3, github/codeql-action/autobuild@v3, github/codeql-action/init@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
CodeQL Analysis (typescript)
Failed to save: Unable to reserve cache with key codeql-trap-1-2.25.1-javascript-2e254ac19a696394030601bc602f54945b12bfc4, another job may be creating this cache.
|
|
CodeQL Analysis (typescript)
Failed to upload database for javascript: Resource not accessible by integration - https://docs.github.com/rest
|
|
CodeQL Analysis (typescript)
1 issue was detected with this workflow: CodeQL language 'javascript' is referenced by more than one entry in the 'language' matrix parameter for job 'codeql'. This may result in duplicate alerts. Please edit the 'language' matrix parameter to keep only one of the following: 'javascript', 'typescript'.
|
|
CodeQL Analysis (typescript)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
codeql-results-javascript
|
150 KB |
sha256:aef58629cf978e1bd5f166479a5c5bcd30c6ff5bbf6e3a937e231b3acf162340
|
|
|
codeql-results-typescript
|
150 KB |
sha256:165d5d3a2943c62e78bda4cb08e1bbfcbfd9e4a352e0a15b016d95eda880d944
|
|
|
sbom.spdx.json
|
374 KB |
sha256:a4f39de5fec99c1b6c7be7a486b5fc27e394b9002674f25fd317f40a7edce137
|
|
|
trivy-secrets-results
|
474 Bytes |
sha256:48ac5dff2b6059eaecbe2390ba9615e18888740fade5aa296075746ae351fb5c
|
|