Skip to content

deps(deps): bump the actions-updates group across 1 directory with 9 updates#97

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-updates-7b0e5835bc
Open

deps(deps): bump the actions-updates group across 1 directory with 9 updates#97
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-updates-7b0e5835bc

deps(deps): bump the actions-updates group across 1 directory with 9 …

a37a8cb
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Jul 21, 2026 in 51s

Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 72 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe3&open=AZ-CrDv54ahQirlofOe3&pullRequest=97

Check warning on line 53 in .github/workflows/security.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDy04ahQirlofOfP&open=AZ-CrDy04ahQirlofOfP&pullRequest=97

Check warning on line 219 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfD&open=AZ-CrDv54ahQirlofOfD&pullRequest=97

Check warning on line 223 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Define exact package version to avoid installing unverified releases.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfF&open=AZ-CrDv54ahQirlofOfF&pullRequest=97

Check warning on line 171 in .github/workflows/cd.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDyr4ahQirlofOfN&open=AZ-CrDyr4ahQirlofOfN&pullRequest=97

Check warning on line 128 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe7&open=AZ-CrDv54ahQirlofOe7&pullRequest=97

Check warning on line 53 in .github/workflows/security.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDy04ahQirlofOfO&open=AZ-CrDy04ahQirlofOfO&pullRequest=97

Check warning on line 128 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe8&open=AZ-CrDv54ahQirlofOe8&pullRequest=97

Check warning on line 72 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe4&open=AZ-CrDv54ahQirlofOe4&pullRequest=97

Check warning on line 227 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Define exact package version to avoid installing unverified releases.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfH&open=AZ-CrDv54ahQirlofOfH&pullRequest=97

Check warning on line 231 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Define exact package version to avoid installing unverified releases.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfJ&open=AZ-CrDv54ahQirlofOfJ&pullRequest=97

Check warning on line 127 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe5&open=AZ-CrDv54ahQirlofOe5&pullRequest=97

Check warning on line 147 in .github/workflows/cd.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDyr4ahQirlofOfL&open=AZ-CrDyr4ahQirlofOfL&pullRequest=97

Check warning on line 36 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe1&open=AZ-CrDv54ahQirlofOe1&pullRequest=97

Check warning on line 147 in .github/workflows/cd.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDyr4ahQirlofOfK&open=AZ-CrDyr4ahQirlofOfK&pullRequest=97

Check warning on line 127 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe6&open=AZ-CrDv54ahQirlofOe6&pullRequest=97

Check warning on line 196 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe_&open=AZ-CrDv54ahQirlofOe_&pullRequest=97

Check warning on line 223 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

"npx" can install packages on-demand and run their lifecycle scripts.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfE&open=AZ-CrDv54ahQirlofOfE&pullRequest=97

Check warning on line 159 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe-&open=AZ-CrDv54ahQirlofOe-&pullRequest=97

Check warning on line 231 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

"npx" can install packages on-demand and run their lifecycle scripts.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfI&open=AZ-CrDv54ahQirlofOfI&pullRequest=97

Check warning on line 36 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe2&open=AZ-CrDv54ahQirlofOe2&pullRequest=97

Check warning on line 197 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" or "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfB&open=AZ-CrDv54ahQirlofOfB&pullRequest=97

Check warning on line 159 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOe9&open=AZ-CrDv54ahQirlofOe9&pullRequest=97

Check warning on line 171 in .github/workflows/cd.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDyr4ahQirlofOfM&open=AZ-CrDyr4ahQirlofOfM&pullRequest=97

Check warning on line 196 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=nikolay-e_arbitrium-core&issues=AZ-CrDv54ahQirlofOfA&open=AZ-CrDv54ahQirlofOfA&pullRequest=97