Skip to content

Merge pull request #17 from saorsa-labs/feat/protocol-aware-transport… #29

Merge pull request #17 from saorsa-labs/feat/protocol-aware-transport…

Merge pull request #17 from saorsa-labs/feat/protocol-aware-transport… #29

Triggered via push March 13, 2026 22:37
Status Failure
Total duration 4m 40s
Artifacts 4

security.yml

on: push
Dependency Review
Dependency Review
Supply Chain Security
2m 3s
Supply Chain Security
Security Gate
0s
Security Gate
Security Report
6s
Security Report
Fit to window
Zoom out
Zoom in

Annotations

2 errors and 12 warnings
Vulnerability Scan
Code Scanning could not process the submitted SARIF file: could not convert rules: invalid security severity value, is not a number: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Scan
Process completed with exit code 1.
Generate SBOM
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Generate SBOM
The process '/usr/bin/git' failed with exit code 128
Policy Check
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Policy Check
The process '/usr/bin/git' failed with exit code 128
Supply Chain Security
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Supply Chain Security
The process '/usr/bin/git' failed with exit code 128
Vulnerability Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@v4, actions/checkout@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Vulnerability Scan
The process '/usr/bin/git' failed with exit code 128
Vulnerability Scan
Calculated fingerprint of 1e6a61617e045efc:1 for file Cargo.lock line 1, but found existing inconsistent fingerprint value quinn-proto:0.11.13
Vulnerability Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Security Report
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/download-artifact@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Security Report
The process '/usr/bin/git' failed with exit code 128

Artifacts

Produced during runtime
Name Size Digest
audit-results Expired
3.04 KB
sha256:cb8614dbbdddc9c66c9caad4f0c1fa03ef01da2865428e34f620479848a0f800
sbom Expired
284 Bytes
sha256:769d90d0cf35962403269e1c89f1a25543ff64365b6409ba3e0f6e14d74e5d3d
security-report Expired
290 Bytes
sha256:af7a861989a6af323987b8a7fe92a755853ff906b527230a920209d9c8dae5d1
supply-chain-report Expired
293 Bytes
sha256:cb37e8199226f1dd48076faba71ad2e82261e12c81a7ae5192349d829facaa97