Skip to content

Bump Go toolchain to 1.25.11 to resolve std-lib security vulnerabilities #2

Bump Go toolchain to 1.25.11 to resolve std-lib security vulnerabilities

Bump Go toolchain to 1.25.11 to resolve std-lib security vulnerabilities #2

Triggered via pull request June 29, 2026 06:28
Status Failure
Total duration 22s
Artifacts

code-scanning.yml

on: pull_request
Matrix: analyze
Fit to window
Zoom out
Zoom in

Annotations

2 errors and 8 warnings
Analyze (actions)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.25.6/x64/codeql/codeql database init --force-overwrite --db-cluster /home/runner/work/_temp/codeql_databases --source-root=/home/runner/work/github-mcp-server/github-mcp-server --no-calculate-baseline --extractor-include-aliases --language=actions --codescanning-config=/home/runner/work/_temp/user-config.yaml --build-mode=none". Exit code was 2 and error was: A fatal error occurred: Error getting package versions 'github/ccr-actions-queries' to the public GitHub Container registry: HTTP/1.1 403 Forbidden. Response body: '{"errors":[{"code":"DENIED","message":"permission_denied: read_package"}]} ' Do you need to specify a token to authenticate to the registry?. See the logs for more details.
Analyze (go)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.25.6/x64/codeql/codeql database init --force-overwrite --db-cluster /home/runner/work/_temp/codeql_databases --source-root=/home/runner/work/github-mcp-server/github-mcp-server --no-calculate-baseline --extractor-include-aliases --language=go --codescanning-config=/home/runner/work/_temp/user-config.yaml --build-mode=autobuild". Exit code was 2 and error was: A fatal error occurred: Error getting package versions 'github/ccr-go-queries' to the public GitHub Container registry: HTTP/1.1 403 Forbidden. Response body: '{"errors":[{"code":"DENIED","message":"permission_denied: read_package"}]} ' Do you need to specify a token to authenticate to the registry?. See the logs for more details.
Analyze (actions)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, github/codeql-action/init@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Analyze (actions)
Debugging artifacts are unavailable since the 'init' Action failed before it could produce any.
Analyze (actions)
3 diagnostic(s) could not be written to the database and will not appear on the Tool Status Page.
Analyze (actions)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Analyze (go)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, github/codeql-action/init@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Analyze (go)
Debugging artifacts are unavailable since the 'init' Action failed before it could produce any.
Analyze (go)
3 diagnostic(s) could not be written to the database and will not appear on the Tool Status Page.
Analyze (go)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/