Skip to content

Merge remote-tracking branch 'origin/dependabot/github_actions/action… #988

Merge remote-tracking branch 'origin/dependabot/github_actions/action…

Merge remote-tracking branch 'origin/dependabot/github_actions/action… #988

Triggered via push August 31, 2026 14:35
Status Failure
Total duration 19h 23m 6s
Artifacts 5
SAST - Semgrep OWASP Top 10
1m 27s
SAST - Semgrep OWASP Top 10
Dependency Scanning
3m 59s
Dependency Scanning
Container Scanning - Trivy
3m 18s
Container Scanning - Trivy
DAST - OWASP ZAP Baseline
3m 23s
DAST - OWASP ZAP Baseline
Security Dashboard
7s
Security Dashboard
Fit to window
Zoom out
Zoom in

Annotations

7 errors and 10 warnings
SAST - Semgrep OWASP Top 10
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
11 critical semgrep finding(s) block merge.
Container Scanning - Trivy
Process completed with exit code 1.
Container Scanning - Trivy
7 critical trivy finding(s) block merge.
Dependency Scanning
Process completed with exit code 1.
Dependency Scanning
8 critical dependencies finding(s) block merge.
DAST - OWASP ZAP Baseline
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
SAST - Semgrep OWASP Top 10
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
SAST - Semgrep OWASP Top 10
201 high-severity semgrep finding(s) require security-team review.
Container Scanning - Trivy
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Container Scanning - Trivy
124 high-severity trivy finding(s) require security-team review.
Dependency Scanning
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Dependency Scanning
34 high-severity dependencies finding(s) require security-team review.
DAST - OWASP ZAP Baseline
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Security Dashboard
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Security Dashboard
359 high-severity security finding(s) require security-team review.

Artifacts

Produced during runtime
Name Size Digest
security-container-trivy
171 KB
sha256:d1af135cf4e049ae5fdc495c75ffad1a0ad9f476ca7e54f7cbfd43eadd899fb7
security-dashboard
9.44 KB
sha256:9e8707dec58df9782085c3dc58e77035d5bf574d180de6c1b36a6a5f4e8dd102
security-dast-zap
277 Bytes
sha256:c2621aaa4f2b06395ac397b3a9abffe2622936244d35e9060c353478d8e644db
security-dependency-scan
22.2 KB
sha256:e7780cc27b4a3ea454cba58ff06e13b4760434eb27e01b2f4c89a1f7dd355c51
security-sast-semgrep
146 KB
sha256:9abeaf1f8b7aa078a4fc57fd1ed4b82880dffca00167a866e0029ec88e073ef8