Skip to content

chore(deps): update all non-major dependencies #1938

chore(deps): update all non-major dependencies

chore(deps): update all non-major dependencies #1938

Triggered via pull request March 17, 2026 01:14
Status Failure
Total duration 5m 16s
Artifacts 9

scans.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

2 errors and 11 warnings
trivy-image
Process completed with exit code 1.
grype-container
Failed minimum severity level. Found vulnerabilities with level 'high' or higher
gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L36
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L46
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
grype
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-fs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
syft
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/sbom-action@57aae528053a48a3f6235f2d9461b05fbcb7366d, anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
msdo
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-image
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
grype-container
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
OSV Scanner SARIF file Expired
589 Bytes
sha256:98936b5008548780b62282a7442fafd03a4f7015280d3d0db68b8dc62f33f887
gitleaks-results.sarif
6.64 KB
sha256:971972c171276d044867f093fb97475fb9745d462a8430c0956523a788e0084f
megalinter-reports
696 KB
sha256:3124a4c9cc80430b8dd3528cb531b7aa4013696bdea943a96605b3d886adadff
new-json-results Expired
241 Bytes
sha256:10d824e2fa3bcbe9a1000a3a757a1a4d934a44b003e29ce87fb186f0a750ea07
old-json-results Expired
241 Bytes
sha256:d150e44ad5bb310be4f0cf0cb7894585929635d287430a26d0852101d50d86f6
python-example-app-syft.spdx.json
17.9 KB
sha256:77797c37c7789d7714ebf82bf96b82b9ff718c6c1563bf0aff67a284ddafa7f1
yxtay~python-example-app~BQBJS1.dockerbuild
25.6 KB
sha256:dfebf7d066d15503910b078ed085463433b6575da2de2836d238b4dc61a9b222
yxtay~python-example-app~SVLCPI.dockerbuild
24.7 KB
sha256:32395c7894e4aae9fbe95590677f6c195b7a8f523eba3eb235e5cbc861a030d7
yxtay~python-example-app~VTZWXB.dockerbuild
26.2 KB
sha256:38d54a6b28b1cc628b6625d68861fd28fd37224fa0e8c41310c391cff000c889