Skip to content

CSRF cookie: legacy-AES fallback is skipped ~1 in 256 times because a wrong-mode decrypt doesn't always throw #257

CSRF cookie: legacy-AES fallback is skipped ~1 in 256 times because a wrong-mode decrypt doesn't always throw

CSRF cookie: legacy-AES fallback is skipped ~1 in 256 times because a wrong-mode decrypt doesn't always throw #257

Triggered via issue August 4, 2026 14:18
Status Success
Total duration 20m 20s
Artifacts

bot-triage.yml

on: issues
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
Triage issue
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/create-github-app-token@v2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Triage issue
⚠️ SECURITY WARNING: Bypassing write permission check for bpamiri due to allowed_non_write_users='*'. This should only be used for workflows with very limited permissions.