ci: adding security scans #5
security.yml
on: pull_request
CodeQL Analysis
1m 47s
Go Vulnerability Check
42s
Secret Scanning
6s
Binary Vulnerability Scan
1m 19s
License Check
44s
Annotations
13 errors and 4 warnings
|
Secret Scanning
🛑 missing gitleaks license. Go grab one at gitleaks.io and store it as a GitHub Secret named GITLEAKS_LICENSE. For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
|
|
Go Vulnerability Check
terraform.main calls providerserver.Serve, which eventually calls pem.Decode
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls url.URL.Parse
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls url.ParseRequestURI
|
|
Go Vulnerability Check
client.NewOryClient calls urlx.Parse, which calls url.Parse
|
|
Go Vulnerability Check
terraform.main calls providerserver.Serve, which eventually calls asn1.Unmarshal
|
|
Go Vulnerability Check
client.OryClient.UpdateOAuth2Client calls client.OAuth2APISetOAuth2ClientRequest.Execute, which eventually calls http.Client.Do
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.VerifyHostname
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Go Vulnerability Check
acctest.RunTest calls resource.Test, which eventually calls x509.Certificate.Verify
|
|
Binary Vulnerability Scan
Please verify that the necessary features are enabled: Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
|
|
CodeQL Analysis
Please verify that the necessary features are enabled: Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
|
|
Binary Vulnerability Scan
Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
|
|
Binary Vulnerability Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
CodeQL Analysis
Advanced Security must be enabled for this repository to use code scanning. - https://docs.github.com/rest
|
|
CodeQL Analysis
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|