ci: adding security scans #1
security.yml
on: pull_request
CodeQL Analysis
1m 47s
Go Vulnerability Check
1m 0s
Secret Scanning
7s
Binary Vulnerability Scan
1m 34s
License Check
1m 27s
Annotations
13 errors and 11 warnings
|
Secret Scanning
🛑 missing gitleaks license. Go grab one at gitleaks.io and store it as a GitHub Secret named GITLEAKS_LICENSE. For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
|
|
Go Vulnerability Check
terraform.main calls providerserver.Serve, which eventually calls pem.Decode
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls url.URL.Parse
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls url.ParseRequestURI
|
|
Go Vulnerability Check
client.NewOryClient calls urlx.Parse, which calls url.Parse
|
|
Go Vulnerability Check
terraform.main calls providerserver.Serve, which eventually calls asn1.Unmarshal
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls http.Client.Do
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.VerifyHostname
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Binary Vulnerability Scan
Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run
|
|
CodeQL Analysis
Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run
|
|
Binary Vulnerability Scan
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
Binary Vulnerability Scan
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
Binary Vulnerability Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
|
|
CodeQL Analysis
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|