Security Scanning #24
security.yml
on: schedule
Matrix: CodeQL Security Analysis
Dependency Vulnerability Check
3s
License Compliance Check
3s
Snyk Security Scanning
31s
Secret Detection
2s
ESLint Security Rules
25s
Security Summary
2s
Annotations
8 errors and 15 warnings
|
Secret Detection
Unable to resolve action truffle-security/trufflehog-action, repository not found
|
|
Dependency Vulnerability Check
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
|
License Compliance Check
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
|
Snyk Security Scanning
Path does not exist: snyk.sarif
|
|
Snyk Security Scanning
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
|
Security Summary
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
|
ESLint Security Rules
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Snyk Security Scanning
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/upload-sarif@v2. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Snyk Security Scanning
Resource not accessible by integration
|
|
Snyk Security Scanning
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/analyze@v2, github/codeql-action/autobuild@v2, github/codeql-action/init@v2. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.20.1.
|
|
CodeQL Security Analysis (javascript)
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Resource not accessible by integration
|
|
CodeQL Security Analysis (javascript)
Resource not accessible by integration
|