Skip to content

chore(deps): lock file maintenance (#950) #1973

chore(deps): lock file maintenance (#950)

chore(deps): lock file maintenance (#950) #1973

Triggered via push April 2, 2026 13:38
Status Success
Total duration 11m 37s
Artifacts 7

scans.yml

on: push
Fit to window
Zoom out
Zoom in

Annotations

8 warnings
gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L36
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L46
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
msdo
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-image
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
trivy-fs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
OSV Scanner SARIF file
589 Bytes
sha256:984b4aeb18ad6fd9d6da5f54cfe51239854f1a79a344830c69fcf45624b40364
gitleaks-results.sarif
6.64 KB
sha256:da9a049e078208e5d0b54e62382d333a78c03ccf09f0b71623c4dea16df95426
megalinter-reports
692 KB
sha256:0bcfd32ee5231e33b4354e1ce3bf85c3185c3edb60fd70e0da35ad345a6000be
python-example-app-syft.spdx.json
17.9 KB
sha256:c061d56cfd788630289c251b1c46d8daf4bacd1437e037152054ce5bdd38ddbb
yxtay~python-example-app~JZ1IPJ.dockerbuild
19.8 KB
sha256:0f81fd5954bbe9a1de4ab3dfbacb0d6cf07467e9f8ae5ff46124c10e2de7db6d
yxtay~python-example-app~STZHES.dockerbuild
20.6 KB
sha256:f43f07eb379d3504594a5787156e9f51144cd08aee98897a645ebe96cbf46ecd
yxtay~python-example-app~UUOK2G.dockerbuild
24 KB
sha256:4cd36b35d574d474c2df5518e1e92206cc27c08e9a37f43750ab5666a50200c4