Skip to content

License & Vulnerability Scan #5

License & Vulnerability Scan

License & Vulnerability Scan #5

Triggered via schedule August 31, 2026 10:36
Status Success
Total duration 3m 7s
Artifacts 1

license-vuln-scan.yml

on: schedule
Python license inventory
1m 15s
Python license inventory
Python vulnerability scan (OSV)
7s
Python vulnerability scan (OSV)
Rust vulnerability scan (cargo audit)
3m 3s
Rust vulnerability scan (cargo audit)
Go vulnerability scan (govulncheck)
38s
Go vulnerability scan (govulncheck)
TypeScript vulnerability scan (npm audit)
20s
TypeScript vulnerability scan (npm audit)
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 9 warnings
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.Client.Do, which eventually calls tls.Dialer.DialContext
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.http2transportResponseBody.Close, which eventually calls tls.Conn.Write
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls io.ReadAll, which eventually calls tls.Conn.Read
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.Client.Do, which eventually calls tls.Conn.HandshakeContext
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.cancelTimerBody.Close, which eventually calls asn1.Unmarshal
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.Client.Do, which eventually calls tls.Dialer.DialContext
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.http2transportResponseBody.Close, which eventually calls tls.Conn.Write
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls io.ReadAll, which eventually calls tls.Conn.Read
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.Client.Do, which eventually calls tls.Conn.HandshakeContext
Go vulnerability scan (govulncheck)
go.Client.DeleteWebhook calls http.Client.Do, which eventually calls url.URL.Parse
Python vulnerability scan (OSV)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
TypeScript vulnerability scan (npm audit)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-node@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Go vulnerability scan (govulncheck)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-go@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Python license inventory
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Rust vulnerability scan (cargo audit)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions-rs/toolchain@v1, actions/checkout@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Rust vulnerability scan (cargo audit)
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Rust vulnerability scan (cargo audit)
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Rust vulnerability scan (cargo audit)
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Rust vulnerability scan (cargo audit)
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

Artifacts

Produced during runtime
Name Size Digest
python-license-inventory
1.46 KB
sha256:9868e0b94eec9a0d3fa17cbc3f8c90079f6ab39184c8e8a501652ce194a11dd9