Fix security review followups from #161 #504
security.yml
on: pull_request
Secret Scanning
10s
Trivy Security Scan
57s
Go Security Checker
2m 39s
Dependency Review
5s
Annotations
3 errors and 4 warnings
|
Dependency Review
Dependency review is not supported on this repository. Please ensure that Dependency graph is enabled along with GitHub Advanced Security on private repositories, see https://github.com/basecamp/basecamp-cli/settings/security_analysis
|
|
Trivy Security Scan
Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run
|
|
Go Security Checker
Unable to upload "gosec-results.sarif" as it is not valid SARIF:
- instance.runs[0].tool.driver.rules[5].relationships[0] is not of a type(s) object
- instance.runs[0].tool.driver.rules[6].relationships[0] is not of a type(s) object
- instance.runs[0].tool.driver.rules[7].relationships[0] is not of a type(s) object
|
|
Trivy Security Scan
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
Trivy Security Scan
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
Go Security Checker
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
Go Security Checker
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|