Skip to content

ci(actions): bump aquasecurity/trivy-action from 0.30.0 to 0.36.0 #821

ci(actions): bump aquasecurity/trivy-action from 0.30.0 to 0.36.0

ci(actions): bump aquasecurity/trivy-action from 0.30.0 to 0.36.0 #821

Triggered via pull request August 5, 2026 21:15
Status Failure
Total duration 4m 33s
Artifacts 3

security-scan.yml

on: pull_request
SAST - Semgrep OWASP Top 10
1m 25s
SAST - Semgrep OWASP Top 10
Dependency Scanning
3m 29s
Dependency Scanning
Container Scanning - Trivy
19s
Container Scanning - Trivy
DAST - OWASP ZAP Baseline
20s
DAST - OWASP ZAP Baseline
Security Dashboard
6s
Security Dashboard
Fit to window
Zoom out
Zoom in

Annotations

6 errors and 9 warnings
DAST - OWASP ZAP Baseline
Process completed with exit code 1.
Container Scanning - Trivy
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
11 critical semgrep finding(s) block merge.
Dependency Scanning
Process completed with exit code 1.
Dependency Scanning
8 critical dependencies finding(s) block merge.
DAST - OWASP ZAP Baseline
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Container Scanning - Trivy
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
SAST - Semgrep OWASP Top 10
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/setup-python@v5, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
SAST - Semgrep OWASP Top 10
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
SAST - Semgrep OWASP Top 10
198 high-severity semgrep finding(s) require security-team review.
Dependency Scanning
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/setup-python@v5, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Dependency Scanning
31 high-severity dependencies finding(s) require security-team review.
Security Dashboard
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Security Dashboard
229 high-severity security finding(s) require security-team review.

Artifacts

Produced during runtime
Name Size Digest
security-dashboard
8.03 KB
sha256:b8f9439afad0b07ae351f0157b5200fd35f3e0c33a0fe4c094388d8a8deaf618
security-dependency-scan
20.9 KB
sha256:f0a03ee3f9bb66b6b24567878f4a2e4ebc73cce9b93550c4858096b60c5f38c2
security-sast-semgrep
148 KB
sha256:ceb55822b0eeb184f981ee522e50d270f66f44a5d34b088063618f6eb78f6121