Skip to content

build(uv): bump pytest-env from 1.5.0 to 1.6.0 in the uv group #1926

build(uv): bump pytest-env from 1.5.0 to 1.6.0 in the uv group

build(uv): bump pytest-env from 1.5.0 to 1.6.0 in the uv group #1926

Triggered via pull request March 13, 2026 09:19
Status Success
Total duration 2m 19s
Artifacts 9

scans.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

11 warnings
gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-fs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L36
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L46
When installing a package, its pin version should be defined
msdo
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
grype
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
syft
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/sbom-action@57aae528053a48a3f6235f2d9461b05fbcb7366d, anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-image
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
grype-container
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
OSV Scanner SARIF file Expired
589 Bytes
sha256:e8c65af9e45c813f77e664a3ad841bcd7f8afef33e16f56caf81b8da3c04990d
gitleaks-results.sarif
6.64 KB
sha256:d2b82479292a1e6b9dbfe7497a2ea146da516f1004fa43ca5e3c1debc0b5793d
megalinter-reports
693 KB
sha256:52cd2015fbc8aee65f86687da4de02f0e633de4e66a9354e5973aa1790a77bfd
new-json-results Expired
241 Bytes
sha256:4dab67a00935f9fb5456ba0b4f77d46238980853377eafa5f16f678d4068b7e1
old-json-results Expired
241 Bytes
sha256:c84ff6d22d55fd96cd25dc44283691fa7cda5a685e9c746c0e45130e90538a3e
python-example-app-syft.spdx.json
17.9 KB
sha256:3afbc7c01fc1ab206d4f8c58d50333280d3d14fe24338e423bce7ab68942a5b3
yxtay~python-example-app~CP76R5.dockerbuild
23.7 KB
sha256:2f31fd421dec58181364656978702d799311802ea2b8ac0a6884d25cd01925b2
yxtay~python-example-app~N90ZL5.dockerbuild
23.7 KB
sha256:9c927e12cb7f34d37517347487ba320720f419f33067ef50fabcc6569b110634
yxtay~python-example-app~S16FPR.dockerbuild
24.1 KB
sha256:dcb974ff671196d86511883b041dc9070902097b697330c934399b16d33e5b7d