Enhanced developer experience #2
security-scan.yml
on: pull_request
Secret Detection
8s
Dependency Vulnerability Scan
5s
Dockerfile Security Scan
17s
Docker Compose Security Check
5s
Code Security Analysis
1m 32s
Security Summary
4s
Annotations
4 errors and 3 warnings
|
Dockerfile Security Scan
Invalid SARIF. JSON syntax error: Unexpected end of JSON input
|
|
Dockerfile Security Scan
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
Code Security Analysis
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.20.1/x64/codeql/codeql database finalize --finalize-dataset --threads=4 --ram=14581 /home/runner/work/_temp/codeql_databases/go". Exit code was 32 and last log line was: CodeQL detected code written in Python, but not any written in Go. Confirm that there is some source code for Go in the project. For more information, review our troubleshooting guide at https://gh.io/troubleshooting-code-scanning/no-source-code-seen-during-build . See the logs for more details.
|
|
Code Security Analysis
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
Code Security Analysis
Cache not found for keys: codeql-trap-1-2.20.1-javascript-6c8e0d967831422b90629b8be10e48fd3ee82f98, codeql-trap-1-2.20.1-javascript-
|
|
Code Security Analysis
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.20.1.
|
|
Code Security Analysis
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Resource not accessible by integration
|