feat: Add phase_status tracking and PARTIAL apply status #6760
security.yml
on: pull_request
Go Vulnerability Check
1m 43s
Security Scanner (Gosec)
1m 8s
Trivy Repository Scan
25s
Dependency Review
9s
Generate SBOM
1m 30s
Secret Scanning with Gitleaks
7s
Trivy Container Image Scan
1m 36s
Annotations
10 errors and 8 warnings
|
Go Vulnerability Check
dex.EmbeddedDex.StartServer calls server.NewServer, which eventually calls bitbucketcloud.Config.Open
|
|
Go Vulnerability Check
dex.init calls server.init, which calls authproxy.init
|
|
Go Vulnerability Check
api.Server.Start calls http.Server.Serve, which eventually calls authproxy.callback.LoginURL
|
|
Go Vulnerability Check
api.Server.Start calls http.Server.Serve, which eventually calls authproxy.callback.HandleCallback
|
|
Go Vulnerability Check
dex.EmbeddedDex.StartServer calls server.NewServer, which eventually calls authproxy.Config.Open
|
|
Go Vulnerability Check
dex.init calls server.init, which calls atlassiancrowd.init
|
|
Go Vulnerability Check
dex.New calls memory.memStorage.CreateConnector, which eventually calls atlassiancrowd.crowdConnector.Refresh
|
|
Go Vulnerability Check
api.Server.Start calls http.Server.Serve, which eventually calls atlassiancrowd.crowdConnector.Prompt
|
|
Go Vulnerability Check
api.Server.Start calls http.Server.Serve, which eventually calls atlassiancrowd.crowdConnector.Login
|
|
Go Vulnerability Check
dex.EmbeddedDex.StartServer calls server.NewServer, which eventually calls atlassiancrowd.Config.Open
|
|
Trivy Repository Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Secret Scanning with Gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@v2. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Dependency Review
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/dependency-review-action@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Security Scanner (Gosec)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: bufbuild/buf-setup-action@v1. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Generate SBOM
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: anchore/sbom-action@v0.23.0, bufbuild/buf-setup-action@v1. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Go Vulnerability Check
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: bufbuild/buf-setup-action@v1. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Go Vulnerability Check
Suppressed allowlisted Dex false positive(s) — see ADR-0036
|
|
Trivy Container Image Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809, bufbuild/buf-setup-action@v1. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
gitleaks-results.sarif
|
6.61 KB |
sha256:c5781f80d6808442e798525f92c5615f5ba1a954576f5ada963b1931bc42aa63
|
|
|
meridian_sbom.spdx.json
|
109 KB |
sha256:1dd776a68a365e76a1dcb23d61d1d3ae44edbf05bb0793f185c50b36d6d1bf07
|
|
|
sbom
|
109 KB |
sha256:bb1b02367dbe5fa1f8a2319cd1e6529cde7d84c596d9ebf80a7ed750c3cc6b35
|
|