Skip to content

Security Scanning

Security Scanning #149

Triggered via schedule December 28, 2025 02:50
Status Failure
Total duration 1m 11s
Artifacts 2

security.yml

on: schedule
Matrix: CodeQL Analysis
Secrets Scanning
11s
Secrets Scanning
Dependency Vulnerabilities
25s
Dependency Vulnerabilities
Generate SBOM
7s
Generate SBOM
Security Check Status
2s
Security Check Status
Fit to window
Zoom out
Zoom in

Annotations

5 errors
Secrets Scanning
Process completed with exit code 1.
Secrets Scanning
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
CodeQL Analysis (javascript)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.23.8/x64/codeql/codeql database finalize --finalize-dataset --threads=4 --ram=14581 /home/runner/work/_temp/codeql_databases/javascript". Exit code was 32 and last log line was: CodeQL detected code written in GitHub Actions and Python, but not any written in JavaScript/TypeScript. Confirm that there is some source code for JavaScript/TypeScript in the project. For more information, review our troubleshooting guide at https://gh.io/troubleshooting-code-scanning/no-source-code-seen-during-build . See the logs for more details.
CodeQL Analysis (javascript)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
CodeQL Analysis (python)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/

Artifacts

Produced during runtime
Name Size Digest
devkit-sbom.spdx.json Expired
8.8 KB
sha256:8f82f91ee685b285d52b46ece502ba63991d57411c642d59d065948385deacb1
sbom Expired
8.79 KB
sha256:8d60057f29f3c1aced6eb804efe82befe87ebd75739eb2fe93e69c130519d19f