Skip to content

Using pinned docker image version for nginx alpine (#622) #110

Using pinned docker image version for nginx alpine (#622)

Using pinned docker image version for nginx alpine (#622) #110

Triggered via push April 16, 2026 04:55
Status Failure
Total duration 6m 9s
Artifacts 8
post-merge-pipeline  /  sanitize-project-folder
4s
post-merge-pipeline / sanitize-project-folder
post-merge-pipeline  /  version-bump
6s
post-merge-pipeline / version-bump
post-merge-pipeline  /  run-repo-pipelines
4m 31s
post-merge-pipeline / run-repo-pipelines
post-merge-pipeline  /  trivy-filesystem-scan
32s
post-merge-pipeline / trivy-filesystem-scan
post-merge-pipeline  /  trivy-config-scan
19s
post-merge-pipeline / trivy-config-scan
post-merge-pipeline  /  secrets-gitleaks-scan
20s
post-merge-pipeline / secrets-gitleaks-scan
post-merge-pipeline  /  zizmor-scan
14s
post-merge-pipeline / zizmor-scan
post-merge-pipeline  /  bandit
23s
post-merge-pipeline / bandit
post-merge-pipeline  /  ...  /  notify
post-merge-pipeline / notify-teams / notify
Matrix: post-merge-pipeline / sign-binaries
Matrix: post-merge-pipeline / sign-images
Matrix: post-merge-pipeline / scan-images
Fit to window
Zoom out
Zoom in

Annotations

1 error and 5 warnings
post-merge-pipeline / secrets-gitleaks-scan
Unable to upload "security-results/gitleaks/gitleaks-results-2asqgd.sarif" as it is not valid SARIF: - instance.runs[0].results[0].locations[0].physicalLocation.region.startLine must be greater than or equal to 1 - instance.runs[0].results[0].locations[0].physicalLocation.region.startColumn must be greater than or equal to 1 - instance.runs[0].results[0].locations[0].physicalLocation.region.endLine must be greater than or equal to 1
post-merge-pipeline / trivy-config-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / secrets-gitleaks-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / bandit
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / trivy-filesystem-scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
post-merge-pipeline / scan-images (080137407410.dkr.ecr.us-west-2.amazonaws.com/edge-orch/orch-ui/cluster-orch:4.0.1-dev)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
bandit-results-lmn8wz
527 Bytes
sha256:d0314f2f841cf54dbf83399d42ad7147e711b37ed358ba66852b3ec595775350
cosign-image-f02eec
690 Bytes
sha256:2d2a1fb63ef9a3ce7c89816588dc8629c16d7146b9260f51bcbf97d752952635
docker-images-apps-cluster-orch
353 MB
sha256:eae6327aff1642a8ebd6e75fa03bf21308e9d626a0b3757bd5cee6912d7ad1c2
gitleaks-results-2asqgd-apps-cluster-orch
7.79 KB
sha256:b8a82f67b37cd457b6a01ba7fc7c55d543d32fbc82273d15b8e57123d93ea2d3
trivy-config-scan-apps-cluster-orch
2.02 KB
sha256:1cfc26d08ee9609cc055d8ec59b95c215f6b4f0d2b4664823e4c26dce22d67e9
trivy-fs-scan-report-fs-apps-cluster-orch
531 Bytes
sha256:82d96230221d9395d9d151c5ec11b48b43fe7eab760cb75a9c2dc128fc2e1a29
trivy-image-vuln-080137407410.dkr.ecr.us-west-2.amazonaws.com_edge-orch_orch-ui_cluster-orch_4.0.1-dev
2.57 KB
sha256:61d30ada23ecf230d8fdef90400db43113d2066d82da76491f53c96a712a13cd
trivy-scan-report-sbom-apps-cluster-orch
18.8 KB
sha256:d8fc02628286c9e7b3f3cc168c648742e79f7e297274237a7011f06df697343b