Skip to content

Merge pull request #237 from bountyyfi/dependabot/cargo/rust_xlsxwrit… #455

Merge pull request #237 from bountyyfi/dependabot/cargo/rust_xlsxwrit…

Merge pull request #237 from bountyyfi/dependabot/cargo/rust_xlsxwrit… #455

Triggered via push April 16, 2026 17:17
Status Failure
Total duration 17m 54s
Artifacts 7

security.yml

on: push
License & Dependency Check
19s
License & Dependency Check
Secrets Detection
8s
Secrets Detection
Semgrep SAST
36s
Semgrep SAST
Generate SBOM
2m 27s
Generate SBOM
Dependency Freshness
4m 30s
Dependency Freshness
Security Pattern Analysis
6s
Security Pattern Analysis
Supply Chain Security
7s
Supply Chain Security
OpenSSF Scorecard
37s
OpenSSF Scorecard
Binary Security Analysis
8m 32s
Binary Security Analysis
Fit to window
Zoom out
Zoom in

Annotations

1 error and 6 warnings
Generate SBOM
Resource not accessible by integration - https://docs.github.com/rest
Secrets Detection
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Generate SBOM
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
Generate SBOM
Resource not accessible by integration - https://docs.github.com/rest
Generate SBOM
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
Generate SBOM
Failed minimum severity level. Found vulnerabilities with level 'medium' or higher
Dependency Freshness
23 dependencies are outdated

Artifacts

Produced during runtime
Name Size Digest
binary-security
470 Bytes
sha256:76072944369d3ec0287a83e7d4fc1dc544263164b4f9814019140316a7d39b72
cargo-deny-results
19.2 KB
sha256:3383cbf3ac3434de4e65643e0996eff76aafc3d89b5319cade28f8b6d3360dd1
gitleaks-results.sarif
6.6 KB
sha256:6cb4d26330a1147b656cbbc6582bc8c68fa4f2e0f507ebdd0512030be2e4a34e
outdated-deps
639 Bytes
sha256:da1d85d2db7fc51a3b837a1173abbd43c18059bb38174102a99494dfb7190562
security-report
2.49 KB
sha256:f60ecab72153f09e954373e0999ab0d8cf60f71a7951c43971f5396c5ce404fd
semgrep-results
46.4 KB
sha256:edfeb7d69ea08a93cb589d195dce33b71bdbe8bee86ec5d847088f99fdbe65bf
supply-chain-report
299 Bytes
sha256:afd358e5a12e2c78d603f219f266b7430ed681bec019e03b2134fc9fc66013e5