Skip to content

chore(deps): update github/codeql-action digest to b1bff81 (#947) #1935

chore(deps): update github/codeql-action digest to b1bff81 (#947)

chore(deps): update github/codeql-action digest to b1bff81 (#947) #1935

Triggered via push March 16, 2026 10:26
Status Success
Total duration 2m 33s
Artifacts 7

scans.yml

on: push
Fit to window
Zoom out
Zoom in

Annotations

13 warnings
gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-fs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L36
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L46
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
msdo
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
grype
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-image
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
syft
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/sbom-action@57aae528053a48a3f6235f2d9461b05fbcb7366d, anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
syft
Error uploading depdendency snapshot: { "url": "https://api.github.com/repos/yxtay/python-example-app/dependency-graph/snapshots", "status": 500, "headers": { "access-control-allow-origin": "*", "access-control-expose-headers": "ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset", "content-length": "242", "content-security-policy": "default-src 'none'", "content-type": "application/json; charset=utf-8", "date": "Mon, 16 Mar 2026 10:27:03 GMT", "referrer-policy": "origin-when-cross-origin, strict-origin-when-cross-origin", "server": "github.com", "strict-transport-security": "max-age=31536000; includeSubdomains; preload", "vary": "Accept-Encoding, Accept, X-Requested-With", "x-accepted-github-permissions": "contents=write", "x-content-type-options": "nosniff", "x-frame-options": "deny", "x-github-api-version-selected": "2022-11-28", "x-github-media-type": "github.v3; format=json", "x-github-request-id": "A04B:3AA298:B0577:2D6393:69B7DAF6", "x-ratelimit-limit": "100", "x-ratelimit-remaining": "98", "x-ratelimit-reset": "1773656883", "x-ratelimit-resource": "dependency_snapshots", "x-ratelimit-used": "2", "x-xss-protection": "0" }, "data": { "message": "An error occurred while processing your request. Please try again later.", "documentation_url": "https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository", "status": "500" } }
grype-container
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
grype-container
Failed minimum severity level. Found vulnerabilities with level 'high' or higher

Artifacts

Produced during runtime
Name Size Digest
OSV Scanner SARIF file Expired
589 Bytes
sha256:73a8ec19423300bfa475ec4bdbad1e8b2314f367e07ebf76ba1bc37074181c0b
gitleaks-results.sarif
6.64 KB
sha256:8d9e1d92a2f764e9ab3be7b858701d0063b1f9d8db3eda7de150f9ddfea1517b
megalinter-reports
692 KB
sha256:9f4ad8a93e4e9fa8819026a6e55e9a8ba3f2c398f0486b922f2a7cd01f0347b5
python-example-app-syft.spdx.json
17.9 KB
sha256:fa4bb0cb05262125cf870516b12862fd05507f4f298e6fafe839b7acd97f0fe1
yxtay~python-example-app~BM0CH8.dockerbuild
20 KB
sha256:b6b4b71e3daba08953b892e9634cd1d7c521713944e55ff4602463d7deaeb6bb
yxtay~python-example-app~R1J099.dockerbuild
19.5 KB
sha256:318a686a7ccb7d868400501727afee6bbcfa6691b72275769ae37a9dfb95e726
yxtay~python-example-app~V3P20T.dockerbuild
19.2 KB
sha256:613e7f019eb160235efc95dfda05523a7ab1c620668455723bcc81f51ff9a017