Skip to content

ci(actions): bump actions/checkout from 4 to 7 #1049

ci(actions): bump actions/checkout from 4 to 7

ci(actions): bump actions/checkout from 4 to 7 #1049

Triggered via pull request September 2, 2026 21:14
Status Failure
Total duration 4m 3s
Artifacts 3

security-scan.yml

on: pull_request
SAST - Semgrep OWASP Top 10
1m 38s
SAST - Semgrep OWASP Top 10
Dependency Scanning
3m 45s
Dependency Scanning
Container Scanning - Trivy
18s
Container Scanning - Trivy
DAST - OWASP ZAP Baseline
21s
DAST - OWASP ZAP Baseline
Security Dashboard
9s
Security Dashboard
Fit to window
Zoom out
Zoom in

Annotations

6 errors and 9 warnings
Container Scanning - Trivy
Process completed with exit code 1.
DAST - OWASP ZAP Baseline
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
Process completed with exit code 1.
SAST - Semgrep OWASP Top 10
11 critical semgrep finding(s) block merge.
Dependency Scanning
Process completed with exit code 1.
Dependency Scanning
8 critical dependencies finding(s) block merge.
Container Scanning - Trivy
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
DAST - OWASP ZAP Baseline
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/setup-node@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
SAST - Semgrep OWASP Top 10
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/setup-python@v5, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
SAST - Semgrep OWASP Top 10
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
SAST - Semgrep OWASP Top 10
205 high-severity semgrep finding(s) require security-team review.
Dependency Scanning
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/setup-node@v4, actions/setup-python@v5, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Dependency Scanning
35 high-severity dependencies finding(s) require security-team review.
Security Dashboard
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Security Dashboard
240 high-severity security finding(s) require security-team review.

Artifacts

Produced during runtime
Name Size Digest
security-dashboard
8.56 KB
sha256:2fb1e078551a600ba42e673dc22be5ee4e6447399ca873930cf2207c51c26c97
security-dependency-scan
17.7 KB
sha256:7240a70e5b5d8c21d7fe7b2a7a39cdd46d5061b5e21a6fd9486cb41cff9e945d
security-sast-semgrep
148 KB
sha256:35a08780ae18ec2c6df4e00234c76394ceb2abf880761e8113203015daead7c2