Security Scanning #149
security.yml
on: schedule
Matrix: CodeQL Analysis
Secrets Scanning
11s
Dependency Vulnerabilities
25s
Generate SBOM
7s
Security Check Status
2s
Annotations
5 errors
|
Secrets Scanning
Process completed with exit code 1.
|
|
Secrets Scanning
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
|
|
CodeQL Analysis (javascript)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.23.8/x64/codeql/codeql database finalize --finalize-dataset --threads=4 --ram=14581 /home/runner/work/_temp/codeql_databases/javascript". Exit code was 32 and last log line was: CodeQL detected code written in GitHub Actions and Python, but not any written in JavaScript/TypeScript. Confirm that there is some source code for JavaScript/TypeScript in the project. For more information, review our troubleshooting guide at https://gh.io/troubleshooting-code-scanning/no-source-code-seen-during-build . See the logs for more details.
|
|
CodeQL Analysis (javascript)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
CodeQL Analysis (python)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
devkit-sbom.spdx.json
Expired
|
8.8 KB |
sha256:8f82f91ee685b285d52b46ece502ba63991d57411c642d59d065948385deacb1
|
|
|
sbom
Expired
|
8.79 KB |
sha256:8d60057f29f3c1aced6eb804efe82befe87ebd75739eb2fe93e69c130519d19f
|
|