Skip to content

Updated package-lock.json using npm audit (#620) #108

Updated package-lock.json using npm audit (#620)

Updated package-lock.json using npm audit (#620) #108

Triggered via push April 10, 2026 07:47
Status Failure
Total duration 6m 41s
Artifacts 8
post-merge-pipeline  /  sanitize-project-folder
3s
post-merge-pipeline / sanitize-project-folder
post-merge-pipeline  /  version-bump
8s
post-merge-pipeline / version-bump
post-merge-pipeline  /  run-repo-pipelines
4m 26s
post-merge-pipeline / run-repo-pipelines
post-merge-pipeline  /  trivy-filesystem-scan
26s
post-merge-pipeline / trivy-filesystem-scan
post-merge-pipeline  /  trivy-config-scan
25s
post-merge-pipeline / trivy-config-scan
post-merge-pipeline  /  secrets-gitleaks-scan
18s
post-merge-pipeline / secrets-gitleaks-scan
post-merge-pipeline  /  zizmor-scan
15s
post-merge-pipeline / zizmor-scan
post-merge-pipeline  /  bandit
30s
post-merge-pipeline / bandit
post-merge-pipeline  /  ...  /  notify
post-merge-pipeline / notify-teams / notify
Matrix: post-merge-pipeline / sign-binaries
Matrix: post-merge-pipeline / sign-images
Matrix: post-merge-pipeline / scan-images
Fit to window
Zoom out
Zoom in

Annotations

1 error and 5 warnings
post-merge-pipeline / secrets-gitleaks-scan
Unable to upload "security-results/gitleaks/gitleaks-results-1qcu4u.sarif" as it is not valid SARIF: - instance.runs[0].results[0].locations[0].physicalLocation.region.startLine must be greater than or equal to 1 - instance.runs[0].results[0].locations[0].physicalLocation.region.startColumn must be greater than or equal to 1 - instance.runs[0].results[0].locations[0].physicalLocation.region.endLine must be greater than or equal to 1
post-merge-pipeline / secrets-gitleaks-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / trivy-config-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / trivy-filesystem-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / bandit
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / scan-images (080137407410.dkr.ecr.us-west-2.amazonaws.com/edge-orch/orch-ui/cluster-orch:4.0.1-dev)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
bandit-results-97ykou Expired
527 Bytes
sha256:ce5e14e6e97bad86bef20b32c8d48031d4c92e822843ee35fa10a2c921d718ea
cosign-image-ab99ba
690 Bytes
sha256:b0e608c68b11f153a0357cb51622777c8a0f59debe607446aa4acbb471886bce
docker-images-apps-cluster-orch
351 MB
sha256:c12d4e55a5d3ae0804a81f6a03cf09743fcf19b4442be1a9b64c053a6e9c0b37
gitleaks-results-1qcu4u-apps-cluster-orch Expired
7.76 KB
sha256:44834399e8492e00e179e3e7360358f6deb1b361c1075112d97a64153349918c
trivy-config-scan-apps-cluster-orch
2.02 KB
sha256:d122dbd27431a5b4bae64238e4b27a88a463e81510989a7096d343d78bcb898a
trivy-fs-scan-report-fs-apps-cluster-orch
531 Bytes
sha256:e0a2196e0aa36ebfad28f5fa654e7a653a680dc67b9d9afee5bc79fcf56cf2cc
trivy-image-vuln-080137407410.dkr.ecr.us-west-2.amazonaws.com_edge-orch_orch-ui_cluster-orch_4.0.1-dev
10.5 KB
sha256:3d9a7a22d060b6c317e32febb351ecc3185e68471b0eff21cad460907d70be69
trivy-scan-report-sbom-apps-cluster-orch
17.6 KB
sha256:c6be8eb3cf3a32e5db90c9bbc1960de480fac5292684118022852ac0df30da64